πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Cisco Patch-Palooza Tackles 29 High-Severity Bugs ❌

Patches and workaround fixes address flaws on networking hardware running Cisco IOS XE software.

πŸ“– Read

via "Threatpost".
❌ Feds Hit with Successful Cyberattack, Data Stolen ❌

The attack featured a unique, multistage malware and a likely PulseSecure VPN exploit.

πŸ“– Read

via "Threatpost".
πŸ•΄ Bluetooth Security Weaknesses Pile Up, While Patching Remains Problematic πŸ•΄

Turns out, creating wireless ecosystems for a vast number of different architectures, configurations, and use cases is hard.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Malware Attacks Declined But Became More Evasive in Q2 πŸ•΄

Most of the malware used in attacks last quarter were designed to evade signature-based detection tools, WatchGuard says.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-11086

lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-10585

Pexip Infinity before 18 allows remote Denial of Service (XML parsing).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-10432

Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-17477

Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-11556

Pagure before 5.6 allows XSS via the templates/blame.html blame view.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ WannaCry Has IoT in Its Crosshairs πŸ•΄

The wide variety of devices attached to the Internet of Things offers a rich target for purveyors of ransomware.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ RASP 101: Staying Safe With Runtime Application Self-Protection πŸ•΄

The dream of RASP is to empower applications to protect themselves. How close do current implementations get to living the dream? Here's what to know.

πŸ“– Read

via "Dark Reading: ".
πŸ” Friday Five 9/25 πŸ”

Insider data breaches, COVID contact tracing apps, and FBI indictments - catch up on the week's news with the Friday Five!

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Microsoft Kills 18 Azure Accounts Tied to Nation-State Attacks ❌

An APT group has started heavily relying on cloud services like Azure Active Directory and OneDrive, as well as open-source tools, to obfuscate its attacks.

πŸ“– Read

via "Threatpost".
⚠ Blast from the past! Windows XP source code allegedly leaked online ⚠

Windows XP source code! Fair game to take a peek, or best to look away?

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2018-6449

Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-6448

A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-6447

A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a userÒ€ℒs session and take over the account.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Facebook removes a slew of accounts ahead of the US election πŸ”

These campaigns used tailored messages to target audiences around the globe. As part of the announcement, Facebook also details account followers and advertising spending pertaining to these efforts.

πŸ“– Read

via "Security on TechRepublic".
πŸ” SpyCloud and CyberDefenses join forces on election security effort πŸ”

A cybersecurity company providing services to one in five election jurisdictions across the United States has teamed up with another company to beef up digital protections.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Getting Over the Security-to-Business Communication Gap in DevSecOps πŸ•΄

Application security in a DevOps world takes more than great teamwork among security, developers, and operations staff.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Navigating the Asia-Pacific Threat Landscape: Experts Dive In πŸ•΄

At next week's virtual Black Hat Asia, threat intelligence pros will discuss the threats local organizations should prioritize and how they can prepare.

πŸ“– Read

via "Dark Reading: ".