πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-10596

u'Improper access control can lead signed process to guess pid of other processes and access their address space' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Bitra, Nicobar, QCS605, QCS610, Rennell, SA6155P, Saipan, SC7180, SC8180X, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10562

u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into secure memory and leads to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ6018, Kamorta, MSM8998, Nicobar, QCS404, QCS605, QCS610, Rennell, SA415M, SA6155P, SC7180, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10527

u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address range which could lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA4531, QCA6574AU, QCA8081, QCM2150, QCN7605, QCN7606, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13903

u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, MDM9205, MDM9206, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, SDM450, SM8150

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 8 Frequently Asked Questions on Organizations' Data Protection Programs πŸ•΄

Adherence to data protection regulations requires a multidisciplinary approach that has the commitment of all employees. Expect to be asked questions like these.

πŸ“– Read

via "Dark Reading: ".
❌ Bug in Google Maps Opened Door to Cross-Site Scripting Attacks ❌

A researcher discovered a cross-site scripting flaw in Google Map's export function, which earned him $10,000 in bug bounty rewards.

πŸ“– Read

via "Threatpost".
❌ Cryptobugs Found in Numerous Google Play Store Apps ❌

A new dynamic tool developed by Columbia University researchers flagged cryptography mistakes made in more than 300 popular Android apps.

πŸ“– Read

via "Threatpost".
πŸ•΄ Post-COVID-19 Cybersecurity Spending Update πŸ•΄

Security spending growth will slow in 2020, but purse strings are looser than for other areas of IT.

πŸ“– Read

via "Dark Reading: ".
πŸ” How SMBs are overcoming key challenges in cybersecurity πŸ”

Small and midsized businesses cited budget constraints as their biggest security obstacle, according to Untangle.

πŸ“– Read

via "Security on TechRepublic".
❌ Critical Adobe Flaws Allow Attackers to Run JavaScript in Browsers ❌

Five critical cross-site scripting flaws were fixed by Adobe in Experience Manager as part of its regularly scheduled patches.

πŸ“– Read

via "Threatpost".
πŸ•΄ VPNs: The Cyber Elephant in the Room πŸ•΄

While virtual private networks once boosted security, their current design doesn't fulfill the evolving requirements of today's modern enterprise.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Google Cloud Expands Confidential Computing Lineup πŸ•΄

Google plans to build out its Confidential Computing portfolio with the launch of Confidential GKE Nodes for Kubernetes workloads.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ WordPress Plug-in Has Critical Zero-Day πŸ•΄

The vulnerability in WordPress File Manager could allow a malicious actor to take over the victim's website.

πŸ“– Read

via "Dark Reading: ".
πŸ” Following Data Theft, NJ Hacker Sentenced πŸ”

The hacker admitted last year that he broke into two companies – one his former employer – and stole more than 15,000 files.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Critical Intel Active Management Technology Flaw Allows Privilege Escalation ❌

The critical Intel vulnerability could allow unauthenticated attackers gain escalated privileges on Intel vPro corporate systems.

πŸ“– Read

via "Threatpost".
❌ Microsoft’s Patch Tuesday Packed with Critical RCE Bugs ❌

The most concerning of the disclosed bugs would allow an attacker to take over Microsoft Exchange just by sending an email.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft Fixes 129 Vulnerabilities for September's Patch Tuesday πŸ•΄

This month's Patch Tuesday brought fixes for 23 critical vulnerabilities, including a notable flaw in Microsoft Exchange.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Next-Gen Firewalls 101: Not Just a Buzzword πŸ•΄

In a rare twist, "next-gen" isn't just marketing-speak when it comes to next-gen firewalls, which function differently than traditional gear and may enable you to replace a variety of devices.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-11124

u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max client limit.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCS404, QCS405, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC8180X, SDM660, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

πŸ“– Read

via "National Vulnerability Database".
❌ Spyware Labeled β€˜TikTok Pro’ Exploits Fears of US Ban ❌

Malware can take over common device functions as well as creates a phishing page to steal Facebook credentials.

πŸ“– Read

via "Threatpost".
⚠ Fake web alerts – how to spot and stop them ⚠

How do you spot and deal with fake system alerts on both computers and mobile devices?

πŸ“– Read

via "Naked Security".