🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2020-0238

In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition. This could lead to local escalation of privilege and launching privileged activities with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-150946634

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0108

In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-140108616

📖 Read

via "National Vulnerability Database".
🕴 Researchers Trick Facial-Recognition Systems 🕴

Goal was to see if computer-generated images that look like one person would get classified as another person.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2019-17339

The VirtualRouter component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that theoretically allows an attacker to inject scripts via URLs. The attacker could theoretically social engineer an authenticated user into submitting the URL, thus executing the script on the affected system with the privileges of the user. Affected releases are TIBCO Software Inc.'s TIBCO Silver Fabric: versions 6.0.0 and below.

📖 Read

via "National Vulnerability Database".
Agent Tesla Spyware Adds Fresh Tricks to Its Arsenal

The RAT is surging in 2020, becoming more prevalent than even the infamous TrickBot or Emotet malware.

📖 Read

via "Threatpost".
🔐 Security in the 'new normal': Passwordless is the way forward 🔐

Moving on from passwords to strong authentication and adaptive access policies is key to improving security without hurting productivity, especially given the increase in remote working.

📖 Read

via "Security on TechRepublic".
🔐 Microsoft fixes Windows and Internet Explorer zero-day flaws in latest Patch Tuesday 🔐

The latest series of Patch Tuesday security updates for Windows 10 includes patches for 17 bugs marked 'Critical' and 97 listed as 'Important'.

📖 Read

via "Security on TechRepublic".
TikTok Surreptitiously Collected Android User Data Using Google-Prohibited Tactic

App concealed the practice of gathering device unique identifiers using an added layer of encryption.

📖 Read

via "Threatpost".
🕴 Kr00k, KRACK, and the Seams in Wi-Fi, IoT Encryption 🕴

Black Hat talk expands on research that uncovered more weaknesses in Wi-Fi chips allowing for the unauthorized decryption of traffic.

📖 Read

via "Dark Reading: ".
🕴 Threats vs. Thrift: Running Effective AppSec During a Global Crisis 🕴

By looking at security testing capacity, staff expertise, and risks throughout the software supply chain, application security teams can improve their overall effectiveness.

📖 Read

via "Dark Reading: ".
Citrix Warns of Critical Flaws in XenMobile Server

Citrix said that it anticipates malicious actors "will move quickly to exploit" two critical flaws in its mobile device management software.

📖 Read

via "Threatpost".
🕴 Name That Toon: 'Rise' and Shine 🕴

Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

📖 Read

via "Dark Reading: ".
🕴 SANS Security Training Firm Hit with Data Breach 🕴

A phishing email allowed an attacker to compromise a SANS employee's email environment, the organization reports.

📖 Read

via "Dark Reading: ".
🔐 SANS cybersecurity training firm suffers data breach due to phishing attack 🔐

The breach compromised 28,000 records, exposing such data as names, phone numbers, physical addresses, and email addresses.

📖 Read

via "Security on TechRepublic".
🕴 Using 'Data for Good' to Control the Pandemic 🕴

The tech community should unite to develop and distribute a universal COVID-19 contact-tracing application. Here's why and how.

📖 Read

via "Dark Reading: ".
🔏 Zoom Hit With Lawsuit Over Encryption Claims 🔏

A consumer advocacy group filed a lawsuit against the web conferencing software company alleging it misrepresented the level of security it uses to protect communications.

📖 Read

via "Subscriber Blog RSS Feed ".
🔐 Cybersecurity and remote support are top goals for CIOs in 2020 🔐

Most IT leaders say their priorities have shifted since the coronavirus pandemic surfaced around the start of the year, says Hitachi ID.

📖 Read

via "Security on TechRepublic".
🕴 FireEye Announces New Bug-Bounty Program 🕴

The program, administered by Bugcrowd, will pay bounties of up to $2,500 per vulnerability.

📖 Read

via "Dark Reading: ".
🔐 Abandoned apps like TikTok pose a security risk in a BYOD world 🔐

Social media apps put corporate networks at risk and provide raw material for deep fakes.

📖 Read

via "Security on TechRepublic".
ATENTION New - CVE-2020-0555

Improper input validation for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable escalation of privilege via local access.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-0554

Race condition in software installer for some Intel(R) Wireless Bluetooth(R) products on Windows* 7, 8.1 and 10 may allow an unprivileged user to potentially enable escalation of privilege via local access.

📖 Read

via "National Vulnerability Database".