πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2020-0131

In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely initialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-151159638

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0129

In SetData of btm_ble_multi_adv.cc, there is a possible out-of-bound write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123292010

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0128

In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123940919

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0127

In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the phone process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140054506

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0126

In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local code execution with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137878930

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0124

In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140237592

πŸ“– Read

via "National Vulnerability Database".
❌ Podcast: Would You Use A Contact-Tracing Coronavirus App? ❌

Contact tracing apps for the coronavirus are being developed and tested globally as the world starts to re-open. Are the apps worth using to flatten the curve? Or do data privacy worries trump public health?

πŸ“– Read

via "Threatpost".
⚠ Crooks hijack β€œBlack Lives Matter” to spread zombie malware ⚠

The email says it will let you have your say anonymously about Black Lives Matter.

πŸ“– Read

via "Naked Security".
πŸ›  Haveged 1.9.10 πŸ› 

haveged is a daemon that feeds the /dev/random pool on Linux using an adaptation of the HArdware Volatile Entropy Gathering and Expansion algorithm invented at IRISA. The algorithm is self-tuning on machines with cpuid support, and has been tested in both 32-bit and 64-bit environments. The tarball uses the GNU build mechanism, and includes self test targets and a spec file for those who want to build an RPM.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Siemens Teams Up in OT Endpoint Security πŸ•΄

Machine language-based endpoint security collaboration with SparkCognition is the latest move by Siemens in security.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ The Hitchhiker's Guide to Web App Pen Testing πŸ•΄

Time on your hands and looking to learn about web apps? Here's a list to get you started.

πŸ“– Read

via "Dark Reading: ".
πŸ” FBI warns about cybercriminals exploiting mobile banking apps πŸ”

With increased use, phony apps and banking trojans will try to steal account credentials, according to the FBI.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Siemens and SparkCognition unveil AI-driven cybersecurity solution for ICS endpoints πŸ”

DeepArmor Industrial, fortified by Siemens, increases operational visibility, improves malware detection, and provides protection across a company's fleet of industrial control systems and end points.

πŸ“– Read

via "Security on TechRepublic".
❌ Kubernetes Falls to Cryptomining via Machine-Learning Framework ❌

Misconfigured dashboards are at the heart of a widespread XMRIG Monero-mining campaign.

πŸ“– Read

via "Threatpost".
πŸ” Ad Industry Still Wary of CCPA πŸ”

A handful of advertising trade groups are voicing their dissatisfaction with the CCPA's final proposed regulations, which were sent for review last week.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Two-factor authentication: A cheat sheet πŸ”

A password alone will not protect sensitive information from hackers--two-factor authentication is also necessary. Here's what security pros and users need to know about two-factor authentication.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Protocol Vulnerability Threatens Mobile Networks πŸ•΄

A vuln in the GTP protocol could allow DoS, fraud, and data theft attacks against cellular networks from virtually anywhere.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybersecurity pros are working harder than ever during the pandemic πŸ”

The COVID-19 pandemic has affected many tech career fields. Learn how it has impacted cybersecurity professionals, and how to help.

πŸ“– Read

via "Security on TechRepublic".
❌ Microsoft Outlook Users Targeted By Gamaredon’s New VBA Macro ❌

The Gamaredon APT has started using a new VBA macro to target Microsoft Outlook victims' contact lists.

πŸ“– Read

via "Threatpost".
❌ Black Lives Matter Emails Deliver TrickBot Malware ❌

Malspam emails are claiming to deliver a survey on BLM -- but in reality they deliver the infamous banking trojan.

πŸ“– Read

via "Threatpost".
πŸ•΄ FBI Says Sudden Increase in Mobile Banking Is Heightening Risks For Users πŸ•΄

Mobile malware and fake apps purporting to be legitimate banking software are big risks, law enforcement agency says.

πŸ“– Read

via "Dark Reading: ".