πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Social engineering: A cheat sheet for business professionals πŸ”

People, like computers, can be hacked using a process called social engineering, and there's a good chance a cybersecurity attack on your organization could start with this technique.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2020-11089

In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write). This has been fixed in 2.1.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11088

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11087

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11086

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to an internal structure. This has been fixed in 2.1.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11085

In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11043

In FreeRDP less than or equal to 2.0.0, there is an out-of-bounds read in rfx_process_message_tileset. Invalid data fed to RFX decoder results in garbage on screen (as colors). This has been patched in 2.1.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11040

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound data read from memory in clear_decompress_subcode_rlex, visualized on screen as color. This has been patched in 2.1.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11844

There is an Incorrect Authorization vulnerability in Micro Focus Service Management Automation (SMA) product affecting version 2018.05 to 2020.02. The vulnerability could be exploited to provide unauthorized access to the Container Deployment Foundation.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 15 stories of the week ⚠

From iPhone jailbreaks to questions about the dark web, and everything in between. It's weekly roundup time!

πŸ“– Read

via "Naked Security".
⚠ Facebook to verify identities on accounts that churn out viral posts ⚠

Hopefully it's a COVID-19 version of what it did post-2016 elections, when it required verification of those buying political or issue ads.

πŸ“– Read

via "Naked Security".
⚠ Github uncovers malicious β€˜Octopus Scanner’ targeting developers ⚠

GitHub has uncovered a form of malware that spreads via infected repositories on its system.

πŸ“– Read

via "Naked Security".
πŸ•΄ How AI and Automation Can Help Bridge the Cybersecurity Talent Gap πŸ•΄

Without the right tools and with not enough cybersecurity pros to fill the void, the talent gap will continue to widen.

πŸ“– Read

via "Dark Reading: ".
πŸ” Zoom plans stronger encryption on video meetings for these customers πŸ”

Schools, paying customers and potentially high-risk users could be offered stronger encryption for video meetings under new plans being explored by Zoom.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How Purism takes a lo-fi approach to secure laptops for shipment πŸ”

Are you concerned someone might intercept your newly-purchased mobile device during transit and do bad things with it? Purism is aware this happens and takes a lo-fi approach to the problem.

πŸ“– Read

via "Security on TechRepublic".
❌ Hosting Provider’s Database of Crooked Customers Leaked ❌

Database of sensitive info, including emails and passwords, from owners of Daniel’s Hosting portals could be incriminating.

πŸ“– Read

via "Threatpost".
⚠ No password required! β€œSign in with Apple” account takeover flaw patched ⚠

A bug bounty hunter found a way to login using "Sign in with Apple"... but without the part where you have to put in a password.

πŸ“– Read

via "Naked Security".
❌ Minneapolis Police Department Hack Likely Fake, Says Researcher ❌

Troy Hunt said that the supposed data breach perpetrated by Anonymous is most likely a hoax.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-12033

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12032

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12031

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".