🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2020-11618

THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET protocol.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-11617

The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.

📖 Read

via "National Vulnerability Database".
🔐 Microsoft, Oracle, and Google top list of companies with most vulnerabilities disclosed in Q2 🔐

Two days accounted for 818 vulnerabilities, or 7.3% of the entire midyear's disclosures so far, according to a new report.

📖 Read

via "Security on TechRepublic".
Charming Kitten Returns with WhatsApp, LinkedIn Effort

The Iran-linked APT is targeting Israeli scholars and U.S. government employees in a credential-stealing effort.

📖 Read

via "Threatpost".
🔏 Six Tips to Keep Families Safe Online 🔏

With kids returning to school - many of them remotely - the Federal Trade Commission offered tips for parents to better secure their families online.

📖 Read

via "Subscriber Blog RSS Feed ".
Apple Accidentally Notarizes Shlayer Malware Used in Adware Campaign

The notarized malware payloads were discovered in a recent MacOS adware campaign, disguised as Adobe Flash Player updates.

📖 Read

via "Threatpost".
🕴 Malicious Android Apps Slip Through Google Play Protection 🕴

Multiple Android apps were found spying on users and recruiting victims' devices into ad-fraud botnets.

📖 Read

via "Dark Reading: ".
🕴 Slack Patches Critical Desktop Vulnerability 🕴

The remote code execution flaw could allow a successful attacker to fully control the Slack desktop app on a target machine.

📖 Read

via "Dark Reading: ".
🔐 The best developer-centric security products 🔐

Commentary: For organizations struggling to secure their IT, a host of new, developer-focused products are hitting the market. Check out this guide of the best developer-centric security products.

📖 Read

via "Security on TechRepublic".
🕴 Testing & Automation Pay Off for NSA's DevSecOps Project 🕴

Communication with stakeholders, extensive testing, and robust automation pays dividends for military intelligence agency, one of several presenters at GitLab's virtual Commit conference.

📖 Read

via "Dark Reading: ".
🕴 AI on the Email Offense 🕴

Mass domain purchasing enables email attackers to slip by traditional defenses. Here's how artificial intelligence can stop them.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2020-14178

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-12776

Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie.

📖 Read

via "National Vulnerability Database".
Pioneer Kitten APT Sells Corporate Network Access

The Iran-based APT has infiltrated multiple VPNs using open-source tools and known exploits.

📖 Read

via "Threatpost".
🕴 Poll: Help Wanted 🕴

Is your security team hiring?

📖 Read

via "Dark Reading: ".
🕴 Why Are There Still So Many Windows 7 Devices? 🕴

As the FBI warns, devices become more vulnerable to exploitation as time passes, due to a lack of security updates and new, emerging vulnerabilities.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2018-12475

A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build Service .

📖 Read

via "National Vulnerability Database".
FBI: Ring Smart Doorbells Could Sabotage Cops

While privacy advocates have warned against Ring's partnerships with police, newly unearthed documents reveal FBI concerns about 'new challenges' smart doorbell footage could create for cops.

📖 Read

via "Threatpost".
ATENTION New - CVE-2019-5645

By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can either prevent new HTTP handler sessions from being established, or cause a resource exhaustion on the Metasploit server.

📖 Read

via "National Vulnerability Database".
Magecart Credit-Card Skimmer Adds Telegram as C2 Channel

In a rare move, the encrypted messaging service is being used to send stolen payment-card data from websites back to cybercriminals.

📖 Read

via "Threatpost".
U.S. Voter Databases Offered for Free on Dark Web, Report

Some underground forum users said they're monetizing the information through the State Department's anti-influence-campaign effort.

📖 Read

via "Threatpost".