πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-4650

IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Major US Companies Targeted in New Ransomware Campaign πŸ•΄

Evil Corp. group hit at least 31 customers in campaign to deploy WastedLocker malware, according to Symantec.

πŸ“– Read

via "Dark Reading: ".
πŸ” Congress proposes ban on government use of facial recognition software πŸ”

The Facial Recognition and Biometric Technology Moratorium Act would explicitly ban police from using the technology.

πŸ“– Read

via "Security on TechRepublic".
❌ β€˜Cardplanet’ Operator Sentenced to 9 Years for Selling Stolen Credit Cards ❌

The carding store victimized mainly U.S. citizens and is responsible for $20 million in fraudulent purchases.

πŸ“– Read

via "Threatpost".
πŸ” Safari refinements justify setting the browser as default in macOS Big Sur πŸ”

If Safari isn't your default Mac web browser, it should be when Apple releases macOS Big Sur. Here's how Apple developers have readied the browser for adulthood and the demands of the workplace.

πŸ“– Read

via "Security on TechRepublic".
❌ 8 U.S. City Websites Targeted in Magecart Attacks ❌

Researchers believe that Click2Gov, municipal payment software, may be at the heart of this most recent government security incident.

πŸ“– Read

via "Threatpost".
❌ DarkCrewFriends Returns with Botnet Strategy ❌

The botnet can be used to mount different kinds of attacks, including code-execution and DDoS.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2013-7489

The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 10 stories of the week ⚠

Get yourself up to date with everything we've written in the last seven days - it's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Satori IoT botnet author sentenced to 13 months in prison ⚠

Kenneth Schuchman, the creator of the massive Satori botnet of enslaved devices, will be spending 13 months behind bars.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2019-20414

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20413

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPickerBrowser.jspa page. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20412

The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue Keys; Issue Types; Status Types. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20411

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20410

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the comment restriction feature. The affected versions are before version 7.6.17, from version 7.7.0 before 7.13.9, and from version 8.0.0 before 8.4.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Microsoft Edge browser: This new password monitor helps keep your data safe πŸ”

The new Edge browser will soon warn you if one of your passwords shows up in a data breach -- a feature based on an Azure service that enterprises can already use to protect user passwords.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Non-profit launches new programs to increase diversity in cybersecurity industry πŸ”

Cybersecurity group pivots from speaking engagements and scholarships to analyzing skill gaps and connecting candidates with employers.

πŸ“– Read

via "Security on TechRepublic".
⚠ Beware β€œsecure DNS” scam targeting website owners and bloggers ⚠

If you run a website or a blog, watch out for emails promising "DNSSEC upgrades" - these scammers are after your whole site.

πŸ“– Read

via "Naked Security".
πŸ•΄ Tall Order for Small Businesses: 3 Tips to Find Tailored Security Solutions πŸ•΄

SMBs are responsible for nearly 44% of US economic activity, but given the current climate, it can be difficult for them to find available and/or affordable resources.

πŸ“– Read

via "Dark Reading: ".
πŸ” IBM Research releases differential privacy library that works with machine learning πŸ”

The open-source repository is unique in that most tasks can be run with only a single line of code, according to the company.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-3681

A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed remote attackers that can change downloaded packages to overwrite arbitrary files. This issue affects: SUSE Linux Enterprise Module for Development Tools 15 osc versions prior to 0.169.1-3.20.1. SUSE Linux Enterprise Software Development Kit 12-SP5 osc versions prior to 0.162.1-15.9.1. SUSE Linux Enterprise Software Development Kit 12-SP4 osc versions prior to 0.162.1-15.9.1. openSUSE Leap 15.1 osc versions prior to 0.169.1-lp151.2.15.1. openSUSE Factory osc versions prior to 0.169.0 .

πŸ“– Read

via "National Vulnerability Database".