πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Cloud Leak Exposes 320M Dating-Site Records ❌

A misconfigured, Mailfire-owned Elasticsearch server impacted 70 dating and e-commerce sites, exposing PII and details such as romantic preferences.

πŸ“– Read

via "Threatpost".
πŸ” CISA Breaks Down Recent Chinese Nation State Cyber Activity πŸ”

A new advisory from CISA outlines recent tactics, techniques, and procedures (TTPs) used by Chinese nation state hackers to target US agencies; it also includes ATT&CK Framework TTPs.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2019-14756

An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to the victim that will inject HTML into the email application's UI as soon as the email is opened. At a bare minimum, this allows an attacker to take control over the Email application's UI (e.g., display a malicious prompt to the user asking them to re-enter their email credentials) and also allows an attacker to abuse any of the privileges available to the mobile application.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Security Through an Economics Lens: A Guide for CISOs πŸ•΄

An expert in economics and cybersecurity applies opportunity cost and other concepts of the "dismal science" to infosec roles.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ E-Commerce Sites Hit With New Attack on Magento πŸ•΄

The campaign targeted sites running Magento Version 1, a version of the e-commerce software that is past end-of-life.

πŸ“– Read

via "Dark Reading: ".
❌ Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs ❌

Monday's CISA advisory is a staunch reminder for federal government and private sector entities to apply patches for flaws in F5 BIG-IP devices, Citrix VPNs, Pulse Secure VPNs and Microsoft Exchange servers.

πŸ“– Read

via "Threatpost".
πŸ•΄ Large Cloud Providers Much Less Likely Than Enterprises to Get Breached πŸ•΄

Pen-test results also show a majority of organizations have few protections against attackers already on the network.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Researchers, Companies Slam Mobile Voting Firm Voatz for 'Bad Faith' Attacks πŸ•΄

In a letter, almost 70 different security firms and individual researchers criticize Voatz for misrepresenting to the US Supreme Court widely accepted security research practices.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-14761

An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Note application. At a bare minimum, this allows an attacker to take control over the Note application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14760

An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Recorder application. At a bare minimum, this allows an attacker to take control over the Recorder application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14759

An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Radio application. At a bare minimum, this allows an attacker to take control over the Radio application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14758

An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via email to the victim that will inject HTML into the File Manager application (assuming the victim chooses to download the email attachment). At a bare minimum, this allows an attacker to take control over the File Manager application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14757

An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to the victim that will inject HTML into the Contacts application (assuming the victim chooses to import the file). At a bare minimum, this allows an attacker to take control over the Contacts application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

πŸ“– Read

via "National Vulnerability Database".
❌ MFA Bypass Bugs Opened Microsoft 365 to Attack ❌

Vulnerabilities β€˜that have existed for years’ in WS-Trust could be exploited to attack other services such as Azure and Visual Studio.

πŸ“– Read

via "Threatpost".
πŸ•΄ Simplify Your Privacy Approach to Overcome CCPA Challenges πŸ•΄

By building a privacy-forward culture from the ground up and automating processes, organizations can simplify their approach to privacy and be prepared for any upcoming regulations.

πŸ“– Read

via "Dark Reading: ".
πŸ” Ransomware attacks continue to dominate the threat landscape πŸ”

Cybercriminals are increasingly exploiting the Cobalt Strike testing toolkit to carry out ransomware campaigns, says Cisco Talos Incident Response.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to protect your organization from DDoS attacks πŸ”

Without early threat detection, you may not know your website has been hit by a DDoS attack until it slows down or stops, says NordVPN Teams.

πŸ“– Read

via "Security on TechRepublic".
πŸ” CISOs are struggling to prepare for security compliance audits πŸ”

CISOs are turning to automation to address concerns about doing more with less, preparing for audits remotely, and speeding evidence collection, according to a newly released study.

πŸ“– Read

via "Security on TechRepublic".
❌ Windows Exploit Released For Microsoft β€˜Zerologon’ Flaw ❌

Security researchers and U.S. government authorities alike are urging admins to address Microsoft's critical privilege escalation flaw.

πŸ“– Read

via "Threatpost".
πŸ” Top 5 things to know about zero trust ops πŸ”

Checking users, applications, and devices on your network are just a few ways to keep your company safe from cyberattacks. Tom Merritt lists five things to know about zero trust ops.

πŸ“– Read

via "Security on TechRepublic".