πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-14073

Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overflow when processing large data or non-standard feedback messages in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, SA415M, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SM6150, SM7150, SM8150, SXR1130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14062

Buffer overflows while decoding setup message from Network due to lack of check of IE message length received from network in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, SA415M, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SM6150, SM7150, SM8150, SXR1130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14047

While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8096AU, MDM9607, MSM8909W, MSM8996, MSM8996AU, QCN7605, QCS605, SC8180X, SDA845, SDX20, SDX24, SDX55, SM8150, SXR1130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10626

Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Rennell, Saipan, SC8180X, SDA660, SDA845, SDM429W, SDM439, SDM670, SDM710, SDX20, SDX24, SDX55, SM8150, SM8250, SXR1130, SXR2130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10597

kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, MSM8996, MSM8996AU, Nicobar, QCS605, Rennell, Saipan, SC7180, SC8180X, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

πŸ“– Read

via "National Vulnerability Database".
⚠ Twitter apologizes for leaking businesses’ financial data ⚠

Twitter emailed business clients to tell them that their financial data may have been seen by the uninvited.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2019-20892

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

πŸ“– Read

via "National Vulnerability Database".
⚠ Patch time! NVIDIA fixes kernel driver holes on Windows and Linux ⚠

Kernel driver bugs often let crooks take over your entire system from even the weediest foothold.

πŸ“– Read

via "Naked Security".
πŸ•΄ 'GoldenSpy' Malware Hidden in Tax Software Spies on Companies Doing Business in China πŸ•΄

Advanced persistent threat (APT) campaign aims to steal intelligence secrets from foreign companies operating in China.

πŸ“– Read

via "Dark Reading: ".
πŸ” Why organizations should consider HTTPS inspection to find encrypted malware πŸ”

Some 67% of all malware seen in the first quarter was delivered via HTTPS, according to security firm WatchGuard Technologies.

πŸ“– Read

via "Security on TechRepublic".
❌ Office 365 Users Targeted By β€˜Coronavirus Employee Training’ Phish ❌

Threat actors shift focus from COVID-19 to employee coronavirus training and current events like Black Lives Matter as cyber-attacks continue to rise.

πŸ“– Read

via "Threatpost".
πŸ•΄ Lucifer Malware Aims to Become Broad Platform for Attacks πŸ•΄

The recent spread of the distributed denial-of-service tool attempts to exploit a dozen web-framework flaws, uses credential stuffing, and is intended to work against a variety of operating systems.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Better Collaboration Between Security & Development πŸ•΄

Security and development teams must make it clear why their segment of the development life cycle is relevant to the other teams in the pipeline.

πŸ“– Read

via "Dark Reading: ".
❌ Nvidia Warns Windows Gamers of Serious Graphics Driver Bugs ❌

Several high-severity flaws in Nvidia's GPU display drivers for Windows users could lead to code-execution, DoS and more.

πŸ“– Read

via "Threatpost".
πŸ•΄ Another Record-Breaking DDoS Attack Signals Shift in Criminal Methods πŸ•΄

Malicious botnet sources explode in new attacks that push boundaries in terms of volume and duration.

πŸ“– Read

via "Dark Reading: ".
πŸ” FBI: Online crimes increasing in Florida, California, Texas, Ohio, and New York πŸ”

Analysis of FBI data found that nearly $2 billion was stolen from US victims in 2019 just from business email compromise.

πŸ“– Read

via "Security on TechRepublic".
πŸ” What your personal identity and data are worth on the Dark Web πŸ”

Your credit card is worth around $33, your driver's license around $27, and your PayPal account around $42, according to Reviews.org.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Phishing attacks target workers returning to the office πŸ”

Emails with fake COVID-19 training materials are trying to trick employees into sharing their Microsoft credentials, says Check Point Research.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Vulnerabilities Declining in Open Source, But Slow Patching Still a Problem πŸ•΄

Even as more code is produced, indirect dependencies continue to undermine security.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Contact Tracing & Threat Intel: Broken Tools & Processes πŸ•΄

How epidemiology can solve the people problem in security.

πŸ“– Read

via "Dark Reading: ".