πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 7 Tips for Effective Deception πŸ•΄

The right decoys can frustrate attackers and help detect threats more quickly.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Criminals Turn to IM Platforms to Avoid Law Enforcement Scrutiny πŸ•΄

Researchers from IntSights observed a sharp increase in the use of popular instant messaging apps over the past year among threat groups.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-10379

In Pillow before 6.2.3 and 7.x before 7.0.1, there are two Buffer Overflows in libImaging/TiffDecode.c.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-10378

In libImaging/PcxDecode.c in Pillow before 6.2.3 and 7.x before 7.0.1, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-10177

Pillow before 6.2.3 and 7.x before 7.0.1 has multiple out-of-bounds reads in libImaging/FliDecode.c.

πŸ“– Read

via "National Vulnerability Database".
πŸ” How to use NGINX as a reverse proxy πŸ”

A reverse proxy can do wonders for your network and its security. Learn how to configure NGINX to serve this very purpose.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-19506

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit this vulnerability to cause the device to reboot.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19505

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted hostname, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-16213

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary commands on the system with root privileges.

πŸ“– Read

via "National Vulnerability Database".
⚠ REvil gang threaten to auction celebrity data from Mariah Carey, Lebron James, MTV and more ⚠

The ransomware gang is threatening to auction celebrities' legal documents stolen from the law firm it paralyzed in May.

πŸ“– Read

via "Naked Security".
⚠ Fancy hacking a PlayStation? Sony announces its bug bounty program ⚠

Got a PS4? Like to hack?

πŸ“– Read

via "Naked Security".
❌ TikTok To Stop Clipboard Snooping After Apple Privacy Feature Exposes Behavior ❌

App will stop reading users’ device cut-and-paste data after a new banner alert in an Apple update uncovered the activity.

πŸ“– Read

via "Threatpost".
πŸ•΄ Good Cyber Hygiene in a Post-Pandemic World Starts with Us πŸ•΄

Three ways that security teams can improve processes and collaboration, all while creating the common ground needed to sustain them.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ SOC Wins & Losses πŸ•΄

While the security operations center is enjoying a higher profile these days, just one-fourth of security operations centers actually resolve incidents quickly enough.

πŸ“– Read

via "Dark Reading: ".
❌ Satori Botnet Creator Sentenced to 13 Months in Prison ❌

The creator of the Satori/Okiru, Masuta and Tsunami/Fbot botnets has been sentenced to prison for compromising hundreds of thousands of devices.

πŸ“– Read

via "Threatpost".
πŸ•΄ 5 New InfoSec Job Training Trends: What We're Studying During COVID-19 πŸ•΄

With the pandemic uprooting networks and upending careers, which security skills are hot -- and which are not?

πŸ“– Read

via "Dark Reading: ".
πŸ” Friday Five: 6/26 Edition πŸ”

Files from hundreds of police departments are leaked, FBI issues a security warning to K12 schools, and more - catch up on all the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2019-4650

IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Major US Companies Targeted in New Ransomware Campaign πŸ•΄

Evil Corp. group hit at least 31 customers in campaign to deploy WastedLocker malware, according to Symantec.

πŸ“– Read

via "Dark Reading: ".
πŸ” Congress proposes ban on government use of facial recognition software πŸ”

The Facial Recognition and Biometric Technology Moratorium Act would explicitly ban police from using the technology.

πŸ“– Read

via "Security on TechRepublic".
❌ β€˜Cardplanet’ Operator Sentenced to 9 Years for Selling Stolen Credit Cards ❌

The carding store victimized mainly U.S. citizens and is responsible for $20 million in fraudulent purchases.

πŸ“– Read

via "Threatpost".