🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 CISA Issues Advisory on Home Routers 🕴

The increase in work-from-home employees raises the importance of home router security.

📖 Read

via "Dark Reading: ".
🔐 How to protect your remote desktop environment from brute force attacks 🔐

An RDP compromise provides a cybercriminal with a backdoor for ransomware and other types of malware, says security provider ESET.

📖 Read

via "Security on TechRepublic".
StrongPity APT Back with Kurdish-Aimed Watering Hole Attacks

The spy malware is being delivered via a complex infrastructure with multiple layers, in an effort to avoid analysis.

📖 Read

via "Threatpost".
🕴 Don't Slow Cybersecurity Spending: Steer into the Skid with a Tight Business Plan 🕴

We all know there are slippery conditions ahead, which is why it's never been more important for organizations to maintain and even increase their spending on cybersecurity.

📖 Read

via "Dark Reading: ".
🔏 Inventor of Anti-Corrosion Tech Allegedly Took IP to New Company 🔏

A new lawsuit alleges the chief developer of the company's IP left the company and took some of its confidential information with him to start a new competing company.

📖 Read

via "Subscriber Blog RSS Feed ".
🔐 Developers agree: Application security processes have a negative impact on productivity 🔐

86% of developers polled in a recent survey said every single aspect of appsec hinders their ability to push code.

📖 Read

via "Security on TechRepublic".
🕴 DDoS Attacks Jump 542% from Q4 2019 to Q1 2020 🕴

The shift to remote work and heavy reliance on online services has driven an increase in attacks intended to overwhelm ISPs.

📖 Read

via "Dark Reading: ".
EvilQuest Mac Ransomware Has Keylogger, Crypto Wallet-Stealing Abilities

A rare, new Mac ransomware has been discovered spreading via pirated software packages.

📖 Read

via "Threatpost".
Verizon Media, PayPal, Twitter Top Bug-Bounty Rankings

Verizon Media has paid nearly $10 million to ethical hackers via HackerOne's platform.

📖 Read

via "Threatpost".
🕴 Attackers Will Target Critical PAN-OS Flaw, Security Experts Warn 🕴

After Palo Alto Networks alerted users to a simple-to-exploit vulnerability in its network security gear, security agencies quickly warn that attackers won't wait to jump on it.

📖 Read

via "Dark Reading: ".
🕴 COVID-19 Puts ICS Security Initiatives 'On Pause' 🕴

Security pros concerned that increased remote access to vulnerable operational technology and stalled efforts to harden OT environments puts critical infrastructure at greater risk.

📖 Read

via "Dark Reading: ".
🕴 FCC Designates Huawei & ZTE as National Security Threats 🕴

Backdoors in 5G network equipment from these vendors could enable espionage and malicious activity, agency says.

📖 Read

via "Dark Reading: ".
🕴 Ripple20 Threatens Increasingly Connected Medical Devices 🕴

A series of IoT vulnerabilities could put hospital networks, medical data, and patient safety at risk.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2019-20408

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-10379

In Pillow before 6.2.3 and 7.x before 7.0.1, there are two Buffer Overflows in libImaging/TiffDecode.c.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-10378

In libImaging/PcxDecode.c in Pillow before 6.2.3 and 7.x before 7.0.1, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-10177

Pillow before 6.2.3 and 7.x before 7.0.1 has multiple out-of-bounds reads in libImaging/FliDecode.c.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-20892

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-19506

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit this vulnerability to cause the device to reboot.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-19505

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted hostname, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-16213

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary commands on the system with root privileges.

📖 Read

via "National Vulnerability Database".