πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Citrix Warns of Critical Flaws in XenMobile Server ❌

Citrix said that it anticipates malicious actors "will move quickly to exploit" two critical flaws in its mobile device management software.

πŸ“– Read

via "Threatpost".
πŸ•΄ Name That Toon: 'Rise' and Shine πŸ•΄

Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ SANS Security Training Firm Hit with Data Breach πŸ•΄

A phishing email allowed an attacker to compromise a SANS employee's email environment, the organization reports.

πŸ“– Read

via "Dark Reading: ".
πŸ” SANS cybersecurity training firm suffers data breach due to phishing attack πŸ”

The breach compromised 28,000 records, exposing such data as names, phone numbers, physical addresses, and email addresses.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Using 'Data for Good' to Control the Pandemic πŸ•΄

The tech community should unite to develop and distribute a universal COVID-19 contact-tracing application. Here's why and how.

πŸ“– Read

via "Dark Reading: ".
πŸ” Zoom Hit With Lawsuit Over Encryption Claims πŸ”

A consumer advocacy group filed a lawsuit against the web conferencing software company alleging it misrepresented the level of security it uses to protect communications.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Cybersecurity and remote support are top goals for CIOs in 2020 πŸ”

Most IT leaders say their priorities have shifted since the coronavirus pandemic surfaced around the start of the year, says Hitachi ID.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ FireEye Announces New Bug-Bounty Program πŸ•΄

The program, administered by Bugcrowd, will pay bounties of up to $2,500 per vulnerability.

πŸ“– Read

via "Dark Reading: ".
πŸ” Abandoned apps like TikTok pose a security risk in a BYOD world πŸ”

Social media apps put corporate networks at risk and provide raw material for deep fakes.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2020-0555

Improper input validation for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0554

Race condition in software installer for some Intel(R) Wireless Bluetooth(R) products on Windows* 7, 8.1 and 10 may allow an unprivileged user to potentially enable escalation of privilege via local access.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0553

Out-of-bounds read in kernel mode driver for some Intel(R) Wireless Bluetooth(R) products on Windows* 10, may allow a privileged user to potentially enable information disclosure via local access.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0513

Out of bounds write for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0512

Uncaught exception in the system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable denial of service via local access.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-0510

Out of bounds read in some Intel(R) Graphics Drivers before versions 15.45.31.5127 and 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14630

Reliance on untrusted inputs in a security decision in some Intel(R) Thunderbolt(TM) controllers may allow unauthenticated user to potentially enable information disclosure via physical access.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14620

Insufficient control flow management for some Intel(R) Wireless Bluetooth(R) products may allow an unprivileged user to potentially enable denial of service via adjacent access.

πŸ“– Read

via "National Vulnerability Database".
❌ Amazon Alexa β€˜One-Click’ Attack Can Divulge Personal Data ❌

Researchers disclosed flaws in Amazon Alexa that could allow attackers to access personal data and install skills on Echo devices.

πŸ“– Read

via "Threatpost".
❌ High-Severity TinyMCE Cross-Site Scripting Flaw Fixed ❌

The cross-site scripting flaw could enable arbitrary code execution, information disclosure - and even account takeover.

πŸ“– Read

via "Threatpost".
❌ ReVoLTE Attack Allows Hackers to Listen in on Mobile Calls ❌

Rare attack on cellular protocol exploits an encryption-implementation flaw at base stations to record voice calls.

πŸ“– Read

via "Threatpost".
πŸ•΄ Emotet Return Brings New Tactics & Evasion Techniques πŸ•΄

Security researchers tracking Emotet report its reemergence brings new tricks, including new evasion techniques to bypass security tools.

πŸ“– Read

via "Dark Reading: ".