πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2020-13819

Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.

πŸ“– Read

via "National Vulnerability Database".
❌ High-Severity Android RCE Flaw Fixed in August Security Update ❌

Google addressed high-severity and critical flaws tied to 54 CVEs in this month's Android security bulletin.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft Teams Vulnerable to Patch Workaround, Researchers Report πŸ•΄

Attackers could work around an earlier patch and use Microsoft Teams Updater to download binaries and payloads.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ CISA Offers Tool for Career Navigation πŸ•΄

The new Cyber Career Pathways Tool helps individuals understand the roles in cybersecurity and how to prepare for them.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 3 Tips for Securing Open Source Software πŸ•΄

Maintaining myriad open source components can be tough. Here's how teams can begin to address open source security and continue to innovate.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Attack of the Clone: Next-Gen Social Engineering πŸ•΄

NeoEYED CTO Tamaghna Basu tells us how he created an AI bot to mimic him, how it could be used in social engineering attacks, and what the experience taught him about the value of true human connections.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Building Cybersecurity Strategies in Sub-Saharan Africa πŸ•΄

Evelyn Kilel and Laura Tich of Shehacks Ke discuss how they are working to build cybersecurity strategies that suit the needs and capabilities of developing nations.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Russian Election Interference: What's Next? πŸ•΄

Nate Beach-Westmoreland gives a look back at the past 10 years of Russian election interference and disinformation campaigns. What can we learn from the past and what should we expect as the 2020 US presidential election approaches?

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Voatz Delivers Multi-Layered Security to Protect Electronic Voting πŸ•΄

SPONSORED CONTENT: While electronic voting has been plagued by fears of tampering or fraud, Voatz is looking to make the process more transparent and auditable, according to company founder Nimit Sawhney. He offers learning points from three recent pilots that highlight how governments can improve the integrity and better protect the voting process and its data.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ A Paramedic's Guide to Cybersecurity: Video πŸ•΄

In this video segment, the Dark Reading News Desk speaks to several guests about healthcare cybersecurity. We begin with Rich Mogull, infosec pro and paramedic, for a discussion about what lessons cybersecurity can learn from emergency medical services and the parallels that already exist.

πŸ“– Read

via "Dark Reading: ".
❌ Black Hat 2020: Open-Source AI to Spur Wave of β€˜Synthetic Media’ Attacks ❌

The explosion of open-source AI models are lowering the barrier of entry for bad actors to create fake video, audio and images - and Facebook, Twitter and other platforms aren't ready.

πŸ“– Read

via "Threatpost".
πŸ” Engineer Behind Google, Uber Trade Secret Theft Case Sentenced πŸ”

Anthony Levandowski, the former Google engineer, was sentenced this week, four months after he plead guilty to stealing Google's trade secrets.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2020-15106

In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on this data. Therefore, it is possible to forge an extremely large frame size that can unintentionally panic at the expense of any RAFT participant trying to decode the WAL.

πŸ“– Read

via "National Vulnerability Database".
❌ Black Hat 2020: Scaling Mail-In Voting Spawns Broad Challenges ❌

Voting Village security celeb Matt Blaze delves into the logistics of scaling up mail-in voting ahead of November's election.

πŸ“– Read

via "Threatpost".
πŸ•΄ Voatz Delivers Multilayered Security to Protect Electronic Voting πŸ•΄

SPONSORED CONTENT: While electronic voting has been plagued by fears of tampering or fraud, Voatz is looking to make the process more transparent and auditable, according to company founder Nimit Sawhney. He offers learning points from three recent pilots that highlight how governments can improve the integrity and better protect the voting process and its data.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Pen Testers Share the Inside Story of Their Arrest and Exoneration πŸ•΄

Coalfire's Gary De Mercurio and Justin Wynn share the inside story of their infamous arrest last year while conducting a contracted red-team engagement in an Iowa courthouse -- and what it took to clear their names.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ SynerComm Reboots a Security Staple with 'Continuous' Pen Testing πŸ•΄

SPONSORED CONTENT: Penetration testing has evolved well beyond a couple guys you hire to try and break into your network, according to SynerComm's Brian Judd. In addition to a service that offers round-the-clock pen testing, SynerComm also provides purple team testing, effectively splitting the difference with red- and blue-team exercises.

πŸ“– Read

via "Dark Reading: ".