πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2020-12821

Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-12736

Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has the option to modify content for the email invitation. If the administrator entered template language code in the subject line, that code could be interpreted by the email generation services, potentially resulting in server-side code injection.

πŸ“– Read

via "National Vulnerability Database".
⚠ Kinda sorta weakened version of EARN IT Act creeps closer ⚠

Critics say the amended bill that's headed for a full Senate hearing still threatens encryption, albeit less blatantly.

πŸ“– Read

via "Naked Security".
πŸ” How managed service providers can pose a risk to their customers πŸ”

The US Secret Service has warned organizations about a rise in hacks of MSPs and offers advice on how to beef up security.

πŸ“– Read

via "Security on TechRepublic".
❌ 15 Billion Credentials Currently Up for Grabs on Hacker Forums ❌

Unprecedented amounts of data for accessing bank accounts and streaming services are being flogged on the dark web.

πŸ“– Read

via "Threatpost".
⚠ Mozilla turns off β€œFirefox Send” following malware abuse reports ⚠

Sadly, the easier and safer you make your file sharing service, the more attractive it becomes to the crooks.

πŸ“– Read

via "Naked Security".
πŸ•΄ A Most Personal Threat: Implantable Devices in Secure Spaces πŸ•΄

Do implantable medical devices pose a threat to secure communication facilities? A Virginia Tech researcher says they do, and the problem is growing.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why Cybersecurity's Silence Matters to Black Lives πŸ•΄

The industry is missing an opportunity to educate the public about bad actors who capitalize off of protest, voting rights education and police brutality petitions through social engineering and phishing attacks.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft Seizes Malicious Domains Used in Mass Office 365 Attacks ❌

The phishing campaign targeted Office 365 accounts in 62 countries, using business-related reports and the coronavirus pandemic as lures.

πŸ“– Read

via "Threatpost".
πŸ” How to encrypt an external drive or card in macOS πŸ”

Looking to encrypt removable storage on macOS, but can't figure out how? Jack Wallen shows you the way to make this work.

πŸ“– Read

via "Security on TechRepublic".
πŸ” BYOD: A trend rife with security concerns πŸ”

Researchers explored the implications of allowing employees to bring their own devices for sensitive work tasks.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2020-14476

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11849

Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix 1. The vulnerability could allow information exposure that can result in an elevation of privilege or an unauthorized access.

πŸ“– Read

via "National Vulnerability Database".
❌ Notorious Hacker β€˜Fxmsp’ Outed After Widespread Access-Dealing ❌

The Kazakh native made headlines last year for hacking McAfee, Symantec and Trend Micro; but the Feds say he's also behind a widespread backdoor operation spanning six continents.

πŸ“– Read

via "Threatpost".
πŸ•΄ Fresh Options for Fighting Fraud in Financial Services πŸ•΄

Fraud prevention requires a consumer-centric, data sharing approach.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-11994

Server-Side Template Injection and arbitrary file disclosure on Camel templating components

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19417

The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19416

The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19415

The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Advanced Attackers Take Aim at Office 365 πŸ•΄

Researchers discuss how adversaries use components of Office 365 that are poorly understood and not closely monitored.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ US Charges Kazakhstani Citizen With Hacking Into More Than 300 Orgs πŸ•΄

The accused man, and members of his cybercriminal group, allegedly made at least $1.5 million hacking into companies and selling access to systems over the past three years.

πŸ“– Read

via "Dark Reading: ".