π΄ What Will Cybersecurity's 'New Normal' Look Like? π΄
π Read
via "Dark Reading: ".
The coronavirus pandemic has forced changes for much of the business world, cybersecurity included. What can we expect going forward?π Read
via "Dark Reading: ".
Dark Reading
What Will Cybersecurity's 'New Normal' Look Like?
The coronavirus pandemic has forced changes for much of the business world, cybersecurity included. What can we expect going forward?
ATENTIONβΌ New - CVE-2019-20847
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any channel.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2019-20846
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2019-20845
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack import.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2019-20844
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2019-20843
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2019-20842
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by admins via SearchAllChannels.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2019-20841
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.π Read
via "National Vulnerability Database".
β News Wrap: Malicious Chrome Extensions Removed, CIA βWoefully Laxβ Security Policies Bashed β
π Read
via "Threatpost".
Insider threats, the CIA's bad security policies, and malicious Chrome extensions were the topics of discussion during this week's news wrap podcast.π Read
via "Threatpost".
Threat Post
News Wrap: Malicious Chrome Extensions Removed, CIA βWoefully Laxβ Security Policies Bashed
Insider threats, the CIA's bad security policies, and malicious Chrome extensions were the topics of discussion during this week's news wrap podcast.
π Many people using email to share files despite lack of security π
π Read
via "Security on TechRepublic".
Those polled by Nordlocker also use cloud services, messaging apps, and external drives to share files.π Read
via "Security on TechRepublic".
TechRepublic
Many people using email to share files despite lack of security
Those polled by Nordlocker also use cloud services, messaging apps, and external drives to share files.
π CCPA: How to prepare for California's new privacy law before enforcement starts July 1 π
π Read
via "Security on TechRepublic".
Companies need to look for PII across all corporate data silos and consider building an automated system to respond to requests from consumers, experts say.π Read
via "Security on TechRepublic".
TechRepublic
CCPA: How to prepare for California's new privacy law before enforcement starts July 1
Companies need to look for PII across all corporate data silos and consider building an automated system to respond to requests from consumers, experts say.
ATENTIONβΌ New - CVE-2018-21262
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-21261
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-21260
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-21259
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-21258
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-21257
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-21255
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-21254
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-21253
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-21251
π Read
via "National Vulnerability Database".
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.π Read
via "National Vulnerability Database".