🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🔏 Fabricator Claims Competitor Poached Employees, Then Data 🔏

One company is alleging a rival shop lured two of its most senior employees away - along with trade secrets, confidential information, and a list of its customers.

📖 Read

via "Subscriber Blog RSS Feed ".
Adobe Patches 18 Critical Flaws in Out-Of-Band Update

Critical vulnerabilities were patched in Adobe After Effects, Illustrator, Premiere Pro, Premiere Rush and Audition.

📖 Read

via "Threatpost".
🕴 83% of Forbes 2000 Companies' Web Domains Are Poorly Protected 🕴

Only a handful have controls against domain-name hijacking, DNS modifications, and other threats, a new CSC study finds.

📖 Read

via "Dark Reading: ".
Qbot Trojan Reappears to Go After U.S. Banking Customers

The 12-year-old malware is still dangerous, sporting advanced evasion techniques.

📖 Read

via "Threatpost".
🕴 Adobe Releases PDF Protected Mode for Document Cloud 🕴

The preview, open to Windows users, opens PDF files in a sandbox to protect users who open malicious Acrobat documents.

📖 Read

via "Dark Reading: ".
🕴 CIA's 'Lax' Security Led to 2017 Compromise of Its Hacking Tools 🕴

Internal CIA report released today shows poor security controls surrounding the intelligence agency's hacking tools.

📖 Read

via "Dark Reading: ".
🕴 'Ripple20' Bugs Plague Enterprise, Industrial & Medical IoT Devices 🕴

Researchers discover 19 vulnerabilities in a TCP/IP software library manufacturers have used in connected devices for 20 years.

📖 Read

via "Dark Reading: ".
🕴 Hosting Provider Hit With Largest-Ever DDoS Attack 🕴

Likely looking to make a statement, attackers targeted specific websites hosted by a single provider with a 1.44 terabit-per-second distributed denial-of-service attack, according to Akamai.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2019-17655

A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.2 and below may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0540

Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0539

Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially enable denial of service via local access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0538

Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable denial of service via network access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0537

Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0536

Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 and Intel(R) TXE versions before 3.1.75 and 4.0.25 may allow an unauthenticated user to potentially enable information disclosure via network access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0535

Improper input validation in Intel(R) AMT versions before 11.8.76, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0534

Improper input validation in the DAL subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an unauthenticated user to potentially enable denial of service via network access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0533

Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0532

Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0531

Improper input validation in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an authenticated user to potentially enable information disclosure via network access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0529

Improper initialization in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processor families may allow an unauthenticated user to potentially enable escalation of privilege via local access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0528

Improper buffer restrictions in BIOS firmware for 7th, 8th, 9th and 10th Generation Intel(R) Core(TM) Processor families may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.

📖 Read

via "National Vulnerability Database".