🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 From Defense to Offense: Giving CISOs Their Due 🕴

In today's unparalleled era of disruption, forward-thinking CISOs can become key to company transformation -- but this means resetting relationships with the board and C-suite.

📖 Read

via "Dark Reading: ".
🛠 Sifter 9.8 🛠

Sifter is a osint, recon, and vulnerability scanner. It combines a plethora of tools within different module sets in order to quickly perform recon tasks, check network firewalling, enumerate remote and local hosts, and scan for the blue vulnerabilities within Microsoft systems and if unpatched, exploits them.

📖 Go!

via "Security Tool Files ≈ Packet Storm".
Critical Slack Bug Allows Access to Private Channels, Conversations

The RCE bug affects versions below 4.4 of the Slack desktop app.

📖 Read

via "Threatpost".
Stolen Fortnite Accounts Earn Hackers Millions Per Year

More than 2 billion breached Fortnite accounts have gone up for sale in underground forums so far in 2020 alone.

📖 Read

via "Threatpost".
🕴 UVA Researcher Charged with Computer Intrusion & Trade Secret Theft 🕴

Chinese national Haizhou Hu was researching bio-mimics and fluid dynamics at the University of Virginia.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2020-12644

OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-12643

OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-11618

THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET protocol.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-11617

The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.

📖 Read

via "National Vulnerability Database".
🔐 Microsoft, Oracle, and Google top list of companies with most vulnerabilities disclosed in Q2 🔐

Two days accounted for 818 vulnerabilities, or 7.3% of the entire midyear's disclosures so far, according to a new report.

📖 Read

via "Security on TechRepublic".
Charming Kitten Returns with WhatsApp, LinkedIn Effort

The Iran-linked APT is targeting Israeli scholars and U.S. government employees in a credential-stealing effort.

📖 Read

via "Threatpost".
🔏 Six Tips to Keep Families Safe Online 🔏

With kids returning to school - many of them remotely - the Federal Trade Commission offered tips for parents to better secure their families online.

📖 Read

via "Subscriber Blog RSS Feed ".
Apple Accidentally Notarizes Shlayer Malware Used in Adware Campaign

The notarized malware payloads were discovered in a recent MacOS adware campaign, disguised as Adobe Flash Player updates.

📖 Read

via "Threatpost".
🕴 Malicious Android Apps Slip Through Google Play Protection 🕴

Multiple Android apps were found spying on users and recruiting victims' devices into ad-fraud botnets.

📖 Read

via "Dark Reading: ".
🕴 Slack Patches Critical Desktop Vulnerability 🕴

The remote code execution flaw could allow a successful attacker to fully control the Slack desktop app on a target machine.

📖 Read

via "Dark Reading: ".
🔐 The best developer-centric security products 🔐

Commentary: For organizations struggling to secure their IT, a host of new, developer-focused products are hitting the market. Check out this guide of the best developer-centric security products.

📖 Read

via "Security on TechRepublic".
🕴 Testing & Automation Pay Off for NSA's DevSecOps Project 🕴

Communication with stakeholders, extensive testing, and robust automation pays dividends for military intelligence agency, one of several presenters at GitLab's virtual Commit conference.

📖 Read

via "Dark Reading: ".
🕴 AI on the Email Offense 🕴

Mass domain purchasing enables email attackers to slip by traditional defenses. Here's how artificial intelligence can stop them.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2020-14178

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-12776

Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie.

📖 Read

via "National Vulnerability Database".
Pioneer Kitten APT Sells Corporate Network Access

The Iran-based APT has infiltrated multiple VPNs using open-source tools and known exploits.

📖 Read

via "Threatpost".