πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Credit-Card Skimmer Seeks Websites Running Microsoft's ASP.NET πŸ•΄

The payment-card skimmer targets websites hosted on Microsoft IIS servers and running the ASP.NET web framework.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-10760

A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-8252

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploitation could lead to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-8251

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploitation could lead to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-8250

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-8249

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-8066

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14900

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

πŸ“– Read

via "National Vulnerability Database".
❌ Android Users Hit with β€˜Undeletable’ Adware ❌

Researchers say that 14.8 percent of Android users who were targeted with mobile malware or adware last year were left with undeletable files.

πŸ“– Read

via "Threatpost".
πŸ•΄ North Korea's Lazarus Group Diversifies Into Card Skimming πŸ•΄

Since at least May 2019, the state-sponsored threat actor has stolen card data from dozens of retailers, including major US firms.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Attackers Scan for Vulnerable BIG-IP Devices After Flaw Disclosure πŸ•΄

The US Cybersecurity and Infrastructure Security Agency encourages organizations to patch a critical flaw in the BIG-IP family of application delivery controllers, as firms find evidence that attackers are scanning for the critical vulnerability.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to ensure the integrity of your encrypted drive while it's hibernating in macOS πŸ”

Enabling full-disk encryption to keep documents secure is highly recommended. By default, macOS does not maintain integrity while hibernating. But there's a fix for that.

πŸ“– Read

via "Security on TechRepublic".
πŸ›  Sifter 7.8 πŸ› 

Sifter is a osint, recon, and vulnerability scanner. It combines a plethora of tools within different module sets in order to quickly perform recon tasks, check network firewalling, enumerate remote and local hosts, and scan for the blue vulnerabilities within Microsoft systems and if unpatched, exploits them.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  Mandos Encrypted File System Unattended Reboot Utility 1.8.12 πŸ› 

The Mandos system allows computers to have encrypted root file systems and at the same time be capable of remote or unattended reboots. The computers run a small client program in the initial RAM disk environment which will communicate with a server over a network. All network communication is encrypted using TLS. The clients are identified by the server using an OpenPGP key that is unique to each client. The server sends the clients an encrypted password. The encrypted password is decrypted by the clients using the same OpenPGP key, and the password is then used to unlock the root file system.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ BEC Busts Take Down Multimillion-Dollar Operations πŸ•΄

The two extraditions of business email compromise attackers indicate a step forward for international law enforcement collaboration.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-15096

In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using "contextIsolation" are affected. There are no app-side workarounds, you must update your Electron version to be protected. This is fixed in versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21.

πŸ“– Read

via "National Vulnerability Database".
⚠ Flashy Nigerian Instagram star extradited to US to face BEC charges ⚠

It's a short jump from a Rolls Royce ride to extradition from the UAE. Goodbye, Dubai, goodbye, Palazzo Versace, hello, Chicago jail cell.

πŸ“– Read

via "Naked Security".
❌ First-Ever Russian BEC Gang, Cosmic Lynx, Uncovered ❌

Researchers warn that Cosmic Lynx targets firms that don't use DMARC and uses a "mergers and acquisitions" pretext that can lead to large sums of money being stolen.

πŸ“– Read

via "Threatpost".
❌ Credit-Card Skimmer Has Unlikely Target: Microsoft ASP.NET Sites ❌

A campaign discovered by Malwarebytes Labs in mid-April has lifted credentials from a number of e-commerce portals.

πŸ“– Read

via "Threatpost".
⚠ Company web names hijacked via outdated cloud DNS records ⚠

Why hack into a server when you can just send vistors to a fake alternative instead?

πŸ“– Read

via "Naked Security".
πŸ•΄ Applying the 80-20 Rule to Cybersecurity πŸ•΄

How security teams can achieve 80% of the benefit for 20% of the work.

πŸ“– Read

via "Dark Reading: ".