πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-18248

BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the productÒ€ℒs client credentials for connecting to the BIOTRONIK Remote Communication infrastructure.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-18246

BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure.

πŸ“– Read

via "National Vulnerability Database".
❌ Unpatched Wi-Fi Extender Opens Home Networks to Remote Control ❌

The Homeplug device, from Tenda, suffers from web server bugs as well as a DoS flaw.

πŸ“– Read

via "Threatpost".
❌ AWS Facial Recognition Platform Misidentified Over 100 Politicians As Criminals ❌

Comparitech’s Paul Bischoff found that Amazon’s facial recognition platform misidentified an alarming number of people, and was racially biased.

πŸ“– Read

via "Threatpost".
πŸ” ID theft: Fake Google alerts are now delivering malware πŸ”

E-mails telling you that your data has been compromised are now sometimes fake. Be careful what you click on.

πŸ“– Read

via "Security on TechRepublic".
πŸ” ID theft: Fake Google alerts are now delivering malware πŸ”

E-mails telling you that your data has been compromised are now sometimes fake. Be careful what you click on.

πŸ“– Read

via "Security on TechRepublic".
❌ Tuesday’s Magento 1 EOL Leaves Clock Ticking on 100K Online Stores ❌

Adobe and payment-card companies are making last-minute pleas for e-commerce sites to update to Magento 2, to avoid Magecart attacks and more.

πŸ“– Read

via "Threatpost".
πŸ•΄ Files Stolen from 945 Websites Discovered on Dark Web πŸ•΄

Researchers who found the archived SQL files estimate up to 14 million people could be affected.

πŸ“– Read

via "Dark Reading: ".
πŸ” 2020 sees rise in invoice and payment fraud BEC attacks πŸ”

Abnormal Security found a 75% increase in this type of campaign in the first three months of the year and a spike of 200% from April to May.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Email Error Leads to Exposed PHI of 11,500 Patients πŸ”

A health plan recently disclosed a data breach of 11,500 patients that was triggered by an email mistake.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Why everyone should care about disinformation campaigns πŸ”

Fortalice CEO and former White House CIO Theresa Payton explains why disinformation is such a potent threat.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Why everyone should care about disinformation campaigns πŸ”

Fortalice CEO and former White House CIO Theresa Payton explains why disinformation is such a potent threat.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-6446

A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications.

πŸ“– Read

via "National Vulnerability Database".
❌ REvil Ransomware Gang Adds Auction Feature for Stolen Data ❌

An anonymous bidding mechanism enhances the REvil group's double-extortion game.

πŸ“– Read

via "Threatpost".
πŸ•΄ HackerOne Reveals Top 10 Bug-Bounty Programs πŸ•΄

Rankings based on total bounties paid, top single bounty paid, time to respond, and more.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Russian Cybercriminal Behind CardPlanet Sentenced to 9 Years πŸ•΄

Aleksei Burkov will go to federal prison for operating two websites built to facilitate payment card fraud, hacking, and other crimes.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ University of California SF Pays Ransom After Medical Servers Hit πŸ•΄

As one of at least three universities hit in June, the school paid $1.14 million to cybercriminals following an attack on "several IT systems" in the UCSF School of Medicine.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-20416

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20415

Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.3, and from version 8.0.0 before 8.1.0.

πŸ“– Read

via "National Vulnerability Database".
⚠ iOS 14 flags TikTok, 53 other apps spying on iPhone clipboards ⚠

TikTok, for one, promised to knock this off months ago but was caught red-handed, still at it, by the new clipboard notification in iOS 14.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2017-18922

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

πŸ“– Read

via "National Vulnerability Database".