Forwarded from ๐ก Cybersecurity & Privacy ๐ก - News
โโ========================
๐ Look look!
These channels ๐จ are amazing!
========================
๐ Look look!
These channels ๐จ are amazing!
========================
โ Monday review โ catch up on our latest articles and videos โ
๐ Read
via "Naked Security".
Our recent articles and videos, all in one place.๐ Read
via "Naked Security".
Naked Security
Monday review โ catch up on our latest articles and videos
Our recent articles and videos, all in one place.
๐ด From Defense to Offense: Giving CISOs Their Due ๐ด
๐ Read
via "Dark Reading: ".
In today's unparalleled era of disruption, forward-thinking CISOs can become key to company transformation -- but this means resetting relationships with the board and C-suite.๐ Read
via "Dark Reading: ".
Dark Reading
From Defense to Offense: Giving CISOs Their Due
In today's unparalleled era of disruption, forward-thinking CISOs can become key to company transformation -- but this means resetting relationships with the board and C-suite.
๐ Sifter 9.8 ๐
๐ Go!
via "Security Tool Files โ Packet Storm".
Sifter is a osint, recon, and vulnerability scanner. It combines a plethora of tools within different module sets in order to quickly perform recon tasks, check network firewalling, enumerate remote and local hosts, and scan for the blue vulnerabilities within Microsoft systems and if unpatched, exploits them.๐ Go!
via "Security Tool Files โ Packet Storm".
Packetstormsecurity
Sifter 9.8 โ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
โ Critical Slack Bug Allows Access to Private Channels, Conversations โ
๐ Read
via "Threatpost".
The RCE bug affects versions below 4.4 of the Slack desktop app.๐ Read
via "Threatpost".
Threat Post
Critical Slack Bug Allows Access to Private Channels, Conversations
The RCE bug affects versions below 4.4 of the Slack desktop app.
โ Stolen Fortnite Accounts Earn Hackers Millions Per Year โ
๐ Read
via "Threatpost".
More than 2 billion breached Fortnite accounts have gone up for sale in underground forums so far in 2020 alone.๐ Read
via "Threatpost".
Threat Post
Stolen Fortnite Accounts Earn Hackers Millions Per Year
More than 2 billion breached Fortnite accounts have gone up for sale in underground forums so far in 2020 alone.
๐ด UVA Researcher Charged with Computer Intrusion & Trade Secret Theft ๐ด
๐ Read
via "Dark Reading: ".
Chinese national Haizhou Hu was researching bio-mimics and fluid dynamics at the University of Virginia.๐ Read
via "Dark Reading: ".
Dark Reading
UVA Researcher Charged with Computer Intrusion & Trade Secret Theft
Chinese national Haizhou Hu was researching bio-mimics and fluid dynamics at the University of Virginia.
ATENTIONโผ New - CVE-2020-12644
๐ Read
via "National Vulnerability Database".
OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2020-12643
๐ Read
via "National Vulnerability Database".
OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2020-11618
๐ Read
via "National Vulnerability Database".
THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET protocol.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2020-11617
๐ Read
via "National Vulnerability Database".
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.๐ Read
via "National Vulnerability Database".
๐ Microsoft, Oracle, and Google top list of companies with most vulnerabilities disclosed in Q2 ๐
๐ Read
via "Security on TechRepublic".
Two days accounted for 818 vulnerabilities, or 7.3% of the entire midyear's disclosures so far, according to a new report.๐ Read
via "Security on TechRepublic".
โ Charming Kitten Returns with WhatsApp, LinkedIn Effort โ
๐ Read
via "Threatpost".
The Iran-linked APT is targeting Israeli scholars and U.S. government employees in a credential-stealing effort.๐ Read
via "Threatpost".
Threat Post
Charming Kitten Returns with WhatsApp, LinkedIn Effort
The Iran-linked APT is targeting Israeli scholars and U.S. government employees in a credential-stealing effort.
๐ Six Tips to Keep Families Safe Online ๐
๐ Read
via "Subscriber Blog RSS Feed ".
With kids returning to school - many of them remotely - the Federal Trade Commission offered tips for parents to better secure their families online.๐ Read
via "Subscriber Blog RSS Feed ".
Digital Guardian
Six Tips to Keep Families Safe Online
With kids returning to school - many of them remotely - the Federal Trade Commission offered tips for parents to better secure their families online.
โ Apple Accidentally Notarizes Shlayer Malware Used in Adware Campaign โ
๐ Read
via "Threatpost".
The notarized malware payloads were discovered in a recent MacOS adware campaign, disguised as Adobe Flash Player updates.๐ Read
via "Threatpost".
Threat Post
Apple Accidentally Notarizes Shlayer Malware Used in Adware Campaign
The notarized malware payloads were discovered in a recent MacOS adware campaign, disguised as Adobe Flash Player updates.
๐ด Malicious Android Apps Slip Through Google Play Protection ๐ด
๐ Read
via "Dark Reading: ".
Multiple Android apps were found spying on users and recruiting victims' devices into ad-fraud botnets.๐ Read
via "Dark Reading: ".
Dark Reading
Malicious Android Apps Slip Through Google Play Protection
Multiple Android apps were found spying on users and recruiting victims' devices into ad-fraud botnets.
๐ด Slack Patches Critical Desktop Vulnerability ๐ด
๐ Read
via "Dark Reading: ".
The remote code execution flaw could allow a successful attacker to fully control the Slack desktop app on a target machine.๐ Read
via "Dark Reading: ".
Dark Reading
Slack Patches Critical Desktop Vulnerability
The remote code execution flaw could allow a successful attacker to fully control the Slack desktop app on a target machine.
๐ The best developer-centric security products ๐
๐ Read
via "Security on TechRepublic".
Commentary: For organizations struggling to secure their IT, a host of new, developer-focused products are hitting the market. Check out this guide of the best developer-centric security products.๐ Read
via "Security on TechRepublic".
TechRepublic
Best Developer-Centric Security Products
Commentary: For organizations struggling to secure their IT, a host of new, developer-focused products are hitting the market. Check out this guide of the best developer-centric security products.
๐ด Testing & Automation Pay Off for NSA's DevSecOps Project ๐ด
๐ Read
via "Dark Reading: ".
Communication with stakeholders, extensive testing, and robust automation pays dividends for military intelligence agency, one of several presenters at GitLab's virtual Commit conference.๐ Read
via "Dark Reading: ".
Dark Reading
Testing & Automation Pay Off for NSA's DevSecOps Project
Communication with stakeholders, extensive testing, and robust automation pays dividends for military intelligence agency, one of several presenters at GitLab's virtual Commit conference.
๐ด AI on the Email Offense ๐ด
๐ Read
via "Dark Reading: ".
Mass domain purchasing enables email attackers to slip by traditional defenses. Here's how artificial intelligence can stop them.๐ Read
via "Dark Reading: ".
Dark Reading
AI on the Email Offense
Mass domain purchasing enables email attackers to slip by traditional defenses. Here's how artificial intelligence can stop them.
ATENTIONโผ New - CVE-2020-14178
๐ Read
via "National Vulnerability Database".
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.๐ Read
via "National Vulnerability Database".