๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
ATENTIONโ€ผ New - CVE-2020-10517

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and was fixed in versions 2.21.6, 2.20.15, and 2.19.21. This vulnerability was reported via the GitHub Bug Bounty program.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ” Microsoft just made securing Windows 10 PCs a whole lot easier for IT admins ๐Ÿ”

New security capabilities designed for SMEs allow IT admins to apply baseline security settings across an organization.

๐Ÿ“– Read

via "Security on TechRepublic".
โŒ DoJ Aims to Seize 280 Cryptocurrency Accounts Used by Hackers โŒ

Complaint details collaboration with China to funnel $250m in stolen funds as part of state-sponsored attacks.

๐Ÿ“– Read

via "Threatpost".
โš  Fake Android notifications โ€“ first Google, then Microsoft affected โš 

Were you woken up by a bogus Android notification from Google or Microsoft this week?

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด Redefining What CISO Success Looks Like ๐Ÿ•ด

Key to this new definition is the principle that security programs are designed to minimize business risk, not to achieve 100% no-risk.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ” Friday Five 8/28 ๐Ÿ”

Ransomware going corporate, Cyber Command changing to a more proactive approach, and cybersecurity professionals weighing in on election security - catch up on all the week's news with the Friday Five.

๐Ÿ“– Read

via "Subscriber Blog RSS Feed ".
๐Ÿ•ด Ransomware Red Flags: 7 Signs You're About to Get Hit ๐Ÿ•ด

Caught off guard by a ransomware attack? Security experts say the warning signs were there all along.

๐Ÿ“– Read

via "Dark Reading: ".
โŒ Elon Musk Confirms, Tesla Factory a Target of Foiled Cyberattack โŒ

A Tesla employee was reportedly approached by a Russian national and asked to install malware on the company's systems.

๐Ÿ“– Read

via "Threatpost".
ATENTIONโ€ผ New - CVE-2019-4579

IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 167236.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2019-4533

IBM Resilient SOAR V38.0 users may experience a denial of service of the SOAR Platform due to a insufficient input validation. IBM X-Force ID: 165589.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2019-18392

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด TA542 Returns With Emotet: What's Different Now ๐Ÿ•ด

Researchers report the TA542 threat group has made code changes to its malware and started targeting new locations with Emotet.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ•ด Aruba Enhances Its Edge Services Platform ๐Ÿ•ด

Enhancements unify IoT, IT, and OT networks so customers to help customers adapt to changing environments and user requirements.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ•ด DNC Warns Campaign Staffers of Dating App Dangers ๐Ÿ•ด

The Democratic National Committee advises against sharing too much work and personal information on popular dating apps.

๐Ÿ“– Read

via "Dark Reading: ".
โŒ Instagram โ€˜Help Centerโ€™ Phishing Scam Pilfers Credentials โŒ

Researchers warn that a phishing scam is targeting Instagram users via direct messages on the app.

๐Ÿ“– Read

via "Threatpost".
๐Ÿ•ด Data Privacy Concerns, Lack of Trust Foil Automated Contact Tracing ๐Ÿ•ด

Efforts to create a technology framework for alerting people to whether they have been exposed to an infectious disease have been hindered by a number of key issues.

๐Ÿ“– Read

via "Dark Reading: ".
โš  Monday review โ€“ catch up on our latest articles and videos โš 

Our recent articles and videos, all in one place.

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด From Defense to Offense: Giving CISOs Their Due ๐Ÿ•ด

In today's unparalleled era of disruption, forward-thinking CISOs can become key to company transformation -- but this means resetting relationships with the board and C-suite.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ›  Sifter 9.8 ๐Ÿ› 

Sifter is a osint, recon, and vulnerability scanner. It combines a plethora of tools within different module sets in order to quickly perform recon tasks, check network firewalling, enumerate remote and local hosts, and scan for the blue vulnerabilities within Microsoft systems and if unpatched, exploits them.

๐Ÿ“– Go!

via "Security Tool Files โ‰ˆ Packet Storm".