🔐 How to install Infection Monkey for breach and attack simulations on your network 🔐
📖 Read
via "Security on TechRepublic".
Have you tested your network using a breach and attack simulator? If not, Jack Wallen shows you how with Infection Monkey.📖 Read
via "Security on TechRepublic".
TechRepublic
How to install Infection Monkey for breach and attack simulations on your network
Have you tested your network using a breach and attack simulator? If not, Jack Wallen shows you how with Infection Monkey.
🛠 Clam AntiVirus Toolkit 0.103.0 🛠
📖 Go!
via "Security Tool Files ≈ Packet Storm".
Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.📖 Go!
via "Security Tool Files ≈ Packet Storm".
Packetstormsecurity
Clam AntiVirus Toolkit 0.103.0 ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
❌ Magecart Attack Impacts More Than 10K Online Shoppers ❌
📖 Read
via "Threatpost".
Close to 2,000 e-commerce sites were infected over the weekend with a payment-card skimmer, maybe the result of a zero-day exploit.📖 Read
via "Threatpost".
Threat Post
Magecart Attack Impacts More Than 10K Online Shoppers
Close to 2,000 e-commerce sites were infected over the weekend with a payment-card skimmer, maybe the result of a zero-day exploit.
🕴 Virginia's Largest School System Hit With Ransomware 🕴
📖 Read
via "Dark Reading: ".
Fairfax County Public Schools has launched an investigation following a ransomware attack on some of its technology systems.📖 Read
via "Dark Reading: ".
Dark Reading
Virginia's Largest School System Hit With Ransomware
Fairfax County Public Schools has launched an investigation following a ransomware attack on some of its technology systems.
ATENTION‼ New - CVE-2018-20432
📖 Read
via "National Vulnerability Database".
D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or modify the configuration.📖 Read
via "National Vulnerability Database".
❌ TikTok Fixes Flaws That Opened Android App to Compromise ❌
📖 Read
via "Threatpost".
The flaws are disclosed as Oracle reportedly partners with TikTok as concerns in the U.S. over spying continue.📖 Read
via "Threatpost".
Threat Post
TikTok Fixes Flaws That Opened Android App to Compromise
The flaws are disclosed as Oracle reportedly partners with TikTok as concerns in the U.S. over spying continue.
ATENTION‼ New - CVE-2019-0233
📖 Read
via "National Vulnerability Database".
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-0230
📖 Read
via "National Vulnerability Database".
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.📖 Read
via "National Vulnerability Database".
❌ Cloud Leak Exposes 320M Dating-Site Records ❌
📖 Read
via "Threatpost".
A misconfigured, Mailfire-owned Elasticsearch server impacted 70 dating and e-commerce sites, exposing PII and details such as romantic preferences.📖 Read
via "Threatpost".
Threat Post
Cloud Leak Exposes 320M Dating-Site Records
A misconfigured, Mailfire-owned Elasticsearch server impacted 70 dating and e-commerce sites, exposing PII and details such as romantic preferences.
🔏 CISA Breaks Down Recent Chinese Nation State Cyber Activity 🔏
📖 Read
via "Subscriber Blog RSS Feed ".
A new advisory from CISA outlines recent tactics, techniques, and procedures (TTPs) used by Chinese nation state hackers to target US agencies; it also includes ATT&CK Framework TTPs.📖 Read
via "Subscriber Blog RSS Feed ".
Digital Guardian
CISA Breaks Down Recent Chinese Nation State Cyber Activity
A new advisory from CISA outlines recent hacking tactics, techniques, and procedures (TTPs) used by Chinese nation state threat actors to target US agencies; it also includes includes ATT&CK Framework TTPs.
ATENTION‼ New - CVE-2019-14756
📖 Read
via "National Vulnerability Database".
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to the victim that will inject HTML into the email application's UI as soon as the email is opened. At a bare minimum, this allows an attacker to take control over the Email application's UI (e.g., display a malicious prompt to the user asking them to re-enter their email credentials) and also allows an attacker to abuse any of the privileges available to the mobile application.📖 Read
via "National Vulnerability Database".
🕴 Security Through an Economics Lens: A Guide for CISOs 🕴
📖 Read
via "Dark Reading: ".
An expert in economics and cybersecurity applies opportunity cost and other concepts of the "dismal science" to infosec roles.📖 Read
via "Dark Reading: ".
Dark Reading
Security Through an Economics Lens: A Guide for CISOs
An expert in economics and cybersecurity applies opportunity cost and other concepts of the dismal science to infosec roles.
🕴 E-Commerce Sites Hit With New Attack on Magento 🕴
📖 Read
via "Dark Reading: ".
The campaign targeted sites running Magento Version 1, a version of the e-commerce software that is past end-of-life.📖 Read
via "Dark Reading: ".
Dark Reading
E-Commerce Sites Hit With New Attack on Magento
The campaign targeted sites running Magento Version 1, a version of the e-commerce software that is past end-of-life.
❌ Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs ❌
📖 Read
via "Threatpost".
Monday's CISA advisory is a staunch reminder for federal government and private sector entities to apply patches for flaws in F5 BIG-IP devices, Citrix VPNs, Pulse Secure VPNs and Microsoft Exchange servers.📖 Read
via "Threatpost".
Threat Post
Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs
Monday's CISA advisory is a staunch reminder for federal government and private sector entities to apply patches for flaws in F5 BIG-IP devices, Citrix VPNs, Pulse Secure VPNs and Microsoft Exchange servers.
🕴 Large Cloud Providers Much Less Likely Than Enterprises to Get Breached 🕴
📖 Read
via "Dark Reading: ".
Pen-test results also show a majority of organizations have few protections against attackers already on the network.📖 Read
via "Dark Reading: ".
Dark Reading
Large Cloud Providers Much Less Likely Than Enterprises to Get Breached
Pen-test results also show a majority of organizations have few protections against attackers already on the network.
🕴 Researchers, Companies Slam Mobile Voting Firm Voatz for 'Bad Faith' Attacks 🕴
📖 Read
via "Dark Reading: ".
In a letter, almost 70 different security firms and individual researchers criticize Voatz for misrepresenting to the US Supreme Court widely accepted security research practices.📖 Read
via "Dark Reading: ".
Dark Reading
Researchers, Companies Slam Mobile Voting Firm Voatz for 'Bad Faith' Attacks
In a letter, almost 70 different security firms and individual researchers criticize Voatz for misrepresenting to the US Supreme Court widely accepted security research practices.
ATENTION‼ New - CVE-2019-14761
📖 Read
via "National Vulnerability Database".
An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Note application. At a bare minimum, this allows an attacker to take control over the Note application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-14760
📖 Read
via "National Vulnerability Database".
An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Recorder application. At a bare minimum, this allows an attacker to take control over the Recorder application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-14759
📖 Read
via "National Vulnerability Database".
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Radio application. At a bare minimum, this allows an attacker to take control over the Radio application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-14758
📖 Read
via "National Vulnerability Database".
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via email to the victim that will inject HTML into the File Manager application (assuming the victim chooses to download the email attachment). At a bare minimum, this allows an attacker to take control over the File Manager application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-14757
📖 Read
via "National Vulnerability Database".
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to the victim that will inject HTML into the Contacts application (assuming the victim chooses to import the file). At a bare minimum, this allows an attacker to take control over the Contacts application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.📖 Read
via "National Vulnerability Database".