πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Microsoft Revamps Windows Insider Preview Bug Bounty Program ❌

Researchers can earn up to $100,000 for finding vulnerabilities in Microsoft's revamped Windows Insider Preview bug bounty program.

πŸ“– Read

via "Threatpost".
πŸ•΄ Ratings for Open Source Projects Aim to Make Software More Secure πŸ•΄

Two companies have teamed up to rate open source projects, but can adopting repository ratings help developers make better decisions regarding open source?

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ ShinyHunters Offers Stolen Data on Dark Web πŸ•΄

The threat actor offers more than 26 million records from a series of data breaches.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-12460

OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its PREV_INUSE flag.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-10643

An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vulnerable web page due to a known issue in a third-party component.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Why security professionals are facing more work stress πŸ”

A lack of time and a lack of executive support are two of the top causes of stress, according to a LogRhythm report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Distance learning makes universities more vulnerable to cyberattack πŸ”

Expert suggests universities take extra care to prevent attacks while students are learning from home.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Distance learning makes universities more vulnerable to cyberattack πŸ”

Expert suggests universities take extra care to prevent attacks while students are learning from home.

πŸ“– Read

via "Security on TechRepublic".
❌ Researchers Warn of High-Severity Dell PowerEdge Server Flaw ❌

A path traversal vulnerability in the iDRAC technology can allow remote attackers to take over control of server operations.

πŸ“– Read

via "Threatpost".
❌ Podcast: Security Lessons Learned In Times of Uncertainty ❌

Derek Manky, Chief, Security Insights & Global Threat Alliances at Fortinet's FortiGuard Labs, discusses the top threats and lessons learned from the first half of 2020.

πŸ“– Read

via "Threatpost".
πŸ•΄ As Businesses Move to the Cloud, Cybercriminals Follow Close Behind πŸ•΄

In the wake of COVID-19, data theft is by far the top tactic, followed by cryptomining and ransomware.

πŸ“– Read

via "Dark Reading: ".
πŸ›  Zeek 3.1.5 πŸ› 

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. While focusing on network security monitoring, Zeek provides a comprehensive platform for more general network traffic analysis as well. Well grounded in more than 15 years of research, Zeek has successfully bridged the traditional gap between academia and operations since its inception. Today, it is relied upon operationally in particular by many scientific environments for securing their cyber-infrastructure. Zeek's user community includes major universities, research labs, supercomputing centers, and open-science communities.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
ATENTIONβ€Ό New - CVE-2019-4731

IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Box announces added security to Box Shield solution with automation classification πŸ”

Using machine learning, Shield automatically scans files and classifies them based on content, detecting and securing sensitive information.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2020-13915

Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-13914

webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to cause a denial of service (Segmentation fault) to the webserver via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-13913

An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.

πŸ“– Read

via "National Vulnerability Database".
⚠ Firefox 79 is out – it’s a double-update month so patch now! ⚠

It's a Blue Moon month for Firefox - the second full update in July!

πŸ“– Read

via "Naked Security".
πŸ” Experts: Devastating ransomware attack on Garmin highlights danger of haphazard breach responses πŸ”

The GPS maker scrambled to contain the aftermath of an attack as employees took to social media to describe what was happening.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Autonomous IT: Less Reacting, More Securing πŸ•΄

Keeping data secure requires a range of skills and perfect execution. AI makes that possible.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 7.5M Banking Customers Affected in Dave Security Breach πŸ•΄

The financial services app confirms user data was compromised in a data breach at its former third-party provider, WayDev.

πŸ“– Read

via "Dark Reading: ".