🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Framing the Security Story: The Simplest Threats Are the Most Dangerous 🕴

Don't be distracted by flashy advanced attacks and ignore the more mundane ones.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2020-15032

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Incidents.php id parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-15031

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php chg parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-15030

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Routes.php rtr parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-15029

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php sn parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-15028

NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Map.php xo parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-11882

The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is to handle deeplinks that can be delivered either via links or by directly calling the activity. However, the deeplink format is not properly validated. This can be abused by an attacker to redirect a user to any page and deliver any content to the user.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-19935

Froala Editor before 3.0.6 allows XSS.

📖 Read

via "National Vulnerability Database".
🕴 Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud 🕴

Cosmic Lynx takes a sophisticated approach to business email compromise and represents a shift in tactics for Russian cybercriminals.

📖 Read

via "Dark Reading: ".
🕴 Drone Path Often Reveals Operator's Location 🕴

The threat posed by drones to critical infrastructure and other operational technology is made more serious by the inability of law enforcement to locate operators, researchers say.

📖 Read

via "Dark Reading: ".
🕴 Microsoft Seizes Domains Used in COVID-19-Themed Attacks 🕴

Court grants company's bid to shut down infrastructure used in recent campaigns against Office 365 users.

📖 Read

via "Dark Reading: ".
🔏 FBI Warns of Increase in Fake, COVID-Related Unemployment Claims 🔏

The Federal Bureau of Investigation said this week that its seen a spike in fraudulent unemployment insurance claims related to the pandemic.

📖 Read

via "Subscriber Blog RSS Feed ".
🔐 CompTIA joins the battle to recruit high school and college students into cybersecurity 🔐

The certification company will host prep sessions for the National Cyber League's cybersecurity competitions for individuals and teams.

📖 Read

via "Security on TechRepublic".
🔐 Why people forget their email passwords the most often 🔐

Many users save their email password and so don't remember it if they have to enter or reset it, says NordPass.

📖 Read

via "Security on TechRepublic".
🕴 Treasury Releases Fraud and Money Mule ID Tips 🕴

A new advisory from FinCEN helps financial institutions spot illicit activities and actors.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2019-20896

WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.

📖 Read

via "National Vulnerability Database".
Keeper Threat Group Rakes in $7M from Hundreds of Compromised E-Commerce Sites

Researchers warn that Keeper, using Magecart code, will launch increasingly sophisticated attacks against online merchants worldwide in the coming months.

📖 Read

via "Threatpost".
BEC Hotshot with Opulent Social Media Presence to Face U.S. Charges

The Nigerian native has been extradited from Dubai after a string of over-the-top Instagram posts.

📖 Read

via "Threatpost".
🕴 EDP Renewables Confirms Ransomware Attack 🕴

Its North American branch was notified of the attack because intruders reportedly gained access to 'at least some information' stored in its systems.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2020-15008

A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user supplied table name with little validation, the table name can be modified to allow arbitrary update commands to be run. Usage of other SQL injection techniques such as timing attacks, it is possible to perform full data extraction as well. Patched in 2020.7 and in a hotfix for 2019.12.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-12821

Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

📖 Read

via "National Vulnerability Database".