π΄ US Sanctions Russian Attackers for 2020 Election Interference π΄
π Read
via "Dark Reading: ".
The move comes as Microsoft publishes research on attack groups and activity attempting to target the Biden and Trump campaigns.π Read
via "Dark Reading: ".
Dark Reading
Vulnerabilities & Threats recent news | Dark Reading
Explore the latest news and expert commentary on Vulnerabilities & Threats, brought to you by the editors of Dark Reading
π΄ Cyber-Risks Explode With Move to Telehealth Services π΄
π Read
via "Dark Reading: ".
The hasty shift to online delivery of primary care services since the COVID-19 outbreak has attracted significant attacker interest.π Read
via "Dark Reading: ".
Dark Reading
Cyber-Risks Explode With Move to Telehealth Services
The hasty shift to online delivery of primary care services since the COVID-19 outbreak has attracted significant attacker interest.
ATENTIONβΌ New - CVE-2014-1420
π Read
via "National Vulnerability Database".
On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to launch a symlink attack, though this is partially mitigated by symlink and hardlink restrictions in Ubuntu. Fixed in 1.1.1188+14.10.20140813.4-0ubuntu1.π Read
via "National Vulnerability Database".
π΄ Fraud Prevention During the Pandemic π΄
π Read
via "Dark Reading: ".
When the economy is disrupted, fraud goes up, so let's not ignore the lessons we can learn from previous downturns.π Read
via "Dark Reading: ".
Dark Reading
Fraud Prevention During the Pandemic
When the economy is disrupted, fraud goes up, so let's not ignore the lessons we can learn from previous downturns.
π Friday Five 9/11 π
π Read
via "Subscriber Blog RSS Feed ".
Initial access brokers, scam domain names, and Brazil's new data protection law - catch up on the week's news with the Friday Five.π Read
via "Subscriber Blog RSS Feed ".
Digital Guardian
Friday Five 9/11
Initial access brokers, scam domain names, and Brazil's new data protection law - catch up on the week's news with the Friday Five.
β Serious Security: Hacking Windows passwords via your wallpaper β
π Read
via "Naked Security".
Themes and wallpapers - how dangerous can they really be?π Read
via "Naked Security".
Naked Security
Serious Security: Hacking Windows passwords via your wallpaper
Themes and wallpapers β how dangerous can they really be?
π΄ Spear-Phishers Leverage Office 365 Ecosystem to Validate Stolen Creds in Real Time π΄
π Read
via "Dark Reading: ".
New attack technique uses Office 365 APIs to cross-check credentials against Azure Active Directory as victim types them in.π Read
via "Dark Reading: ".
Dark Reading
Spear-Phishers Leverage Office 365 Ecosystem to Validate Stolen Creds in Real Time
New attack technique uses Office 365 APIs to cross-check credentials against Azure Active Directory as victim types them in.
ATENTIONβΌ New - CVE-2018-19948
π Read
via "National Vulnerability Database".
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-19947
π Read
via "National Vulnerability Database".
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-19946
π Read
via "National Vulnerability Database".
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.π Read
via "National Vulnerability Database".
β WordPress Plugin Flaw Allows Attackers to Forge Emails β
π Read
via "Threatpost".
The high-severity flaw in the Email Subscribers & Newsletters plugin by Icegram affects more than 100,000 WordPress websites.π Read
via "Threatpost".
Threat Post
WordPress Plugin Flaw Allows Attackers to Forge Emails
The high-severity flaw in the Email Subscribers & Newsletters plugin by Icegram affects more than 100,000 WordPress websites.
π Microsoft detects wave of cyberattacks two months before US presidential election π
π Read
via "Security on TechRepublic".
Hacker groups are ramping up activity as the US heads into the peak of election season. The latest attacks at times bear hallmarks similar to those seen in 2016.π Read
via "Security on TechRepublic".
π How to limit file upload size on NGINX to mitigate DoS attacks π
π Read
via "Security on TechRepublic".
If you have an NGINX site that must allow users to upload files, try this configuration to help prevent possible Denial-of-Service attacks.π Read
via "Security on TechRepublic".
TechRepublic
How to limit file upload size on NGINX to mitigate DoS attacks
If you have an NGINX site that must allow users to upload files, try this configuration to help prevent possible Denial-of-Service attacks.
π How to patch CentOS against BootHole π
π Read
via "Security on TechRepublic".
If you have CentOS servers in your data center, you'll want to make sure to patch them against BootHole. Jack Wallen shows you how.π Read
via "Security on TechRepublic".
TechRepublic
How to patch CentOS against BootHole
If you have CentOS servers in your data center, you'll want to make sure to patch them against BootHole. Jack Wallen shows you how.
π How to hide files from any file manager on the Linux desktop π
π Read
via "Security on TechRepublic".
Want to hide files and folders from your Linux desktop file manager? Jack Wallen shows you one handy method.π Read
via "Security on TechRepublic".
TechRepublic
How to hide files from any file manager on the Linux desktop
Want to hide files and folders from your Linux desktop file manager? Jack Wallen shows you one handy method.
π 22 cybersecurity courses for aspiring and in-demand IT security pros π
π Read
via "Security on TechRepublic".
If you want to land a high-paying cybersecurity job or ace an IT security certification exam, check out these online training courses, which cover GDPR, business continuity, ethical hacking, and more.π Read
via "Security on TechRepublic".
TechRepublic
22 cybersecurity courses for aspiring and in-demand IT security pros
If you want to land a high-paying cybersecurity job or ace an IT security certification exam, check out these online training courses, which cover GDPR, business continuity, ethical hacking, and more.
β Itβs No βGiggleβ: Managing Expectations for Vulnerability Disclosure β
π Read
via "Threatpost".
Vulnerability-disclosure policies (VDPs), if done right, can help provide clarity and clear guidelines to both bug-hunters and vendors when it comes to going public with security flaws.π Read
via "Threatpost".
Threat Post
Itβs No βGiggleβ: Managing Expectations for Vulnerability Disclosure
Vulnerability-disclosure policies (VDPs), if done right, can help provide clarity and clear guidelines to both bug-hunters and vendors when it comes to going public with security flaws.
π΄ Ransomware Hits US District Court in Louisiana π΄
π Read
via "Dark Reading: ".
The ransomware attack has exposed internal documents from the court and knocked its website offline.π Read
via "Dark Reading: ".
Dark Reading
Ransomware Hits US District Court in Louisiana
The ransomware attack has exposed internal documents from the court and knocked its website offline.
π΄ APT Groups Set Sights on Linux Targets: Inside the Trend π΄
π Read
via "Dark Reading: ".
Researchers see more advanced attack groups creating tools and platforms to target Linux-based devices.π Read
via "Dark Reading: ".
Dark Reading
APT Groups Set Sights on Linux Targets: Inside the Trend
Researchers see more advanced attack groups creating tools and platforms to target Linux-based devices.
π΄ 3 Secure Moments: A Tranquil Trio of Security Haiku π΄
π Read
via "Dark Reading: ".
Placid poems to quiet the infosec pro's harried mind. (Or placid, by infosec standards.)π Read
via "Dark Reading: ".
Dark Reading
3 Secure Moments: A Tranquil Trio of Security Haiku
Placid poems to quiet the infosec pros harried mind. (Or placid, by infosec standards.)
ATENTIONβΌ New - CVE-2014-10401
π Read
via "National Vulnerability Database".
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.π Read
via "National Vulnerability Database".