πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-15216 β€Ό

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

πŸ“– Read

via "National Vulnerability Database".
πŸ” Ahead of Election, FBI, CISA Issue Warning on Disinformation Campaigns πŸ”

The FBI and CISA have issued another warning about the 2020 election, asserting that foreign actors are spreading disinformation around hacked voter information.

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Vulnerability in Wireless Router Chipsets Prompts Advisory πŸ•΄

Synopsys issues an advisory for vulnerabilities affecting the chipsets of wireless routers from Qualcomm, Mediatek, and Realtek.

πŸ“– Read

via "Dark Reading".
🦿 FBI says hackers want to stoke doubt about the 2020 election 🦿

In a PSA on Monday, the FBI and CISA warned about the potential for widespread disinformation campaigns in the run-up to November.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Securing Slack: 5 Tips for Safer Messaging, Collaboration πŸ•΄

Remote workers and scattered teams are relying on Slack more and more for messaging and collaboration. Here are a few extra tips for keeping data and systems more secure when using Slack.

πŸ“– Read

via "Dark Reading".
πŸ•΄ New Campaign by China-Linked Group Targets US Orgs for First Time πŸ•΄

In a least one instance, the Palmerworm APT group was able to remain undetected on a compromised system for nearly six months, according to Symantec.

πŸ“– Read

via "Dark Reading".
πŸ•΄ DDoS Attacks Soar in First Half of 2020 πŸ•΄

Shorter, faster, multivector attacks had a greater impact on victims.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft: Ransomware & Nation-State Attacks Rise, Get More Sophisticated πŸ•΄

Malware-based attacks are out, phishing is in, along with credential stuffing and business email compromise. Microsoft recommends defensive tactics in its new report on rising threats.

πŸ“– Read

via "Dark Reading".
❌ Why Web Browser Padlocks Shouldn’t Be Trusted ❌

Popular β€˜safe browsing’ padlocks are now passe as a majority of bad guys also use them.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-5132 β€Ό

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organizationΓƒΒ’Γ’β€šΒ¬Γ’β€žΒ’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Attacker Dwell Time: Ransomware's Most Important Metric πŸ•΄

How to bolster security defenses by zeroing in on the length of time an interloper remains undetected inside your network

πŸ“– Read

via "Dark Reading".
❌ Microsoft Exchange Servers Still Open to Actively Exploited Flaw ❌

Despite Microsoft issuing patches almost eight months ago, 61 percent of Exchange servers are still vulnerable.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-15731 β€Ό

An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefender Engines versions prior to 7.85448.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-17098 β€Ό

Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This issue affects: August Connect Wi-Fi Bridge App version v10.11.0 and prior versions on Android. August Connect Firmware version 2.2.12 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
🦿 The state of security and the evolving role of CISOs in a pandemic 🦿

Cybersecurity leaders discuss business resiliency and identity challenges during a session at VMworld 2020.

πŸ“– Read

via "Tech Republic".
❌ Facebook Small Business Grants Spark Identity-Theft Scam ❌

The cybercrooks spread the COVID-19 relief scam via Telegram and WhatsApp, and ultimately harvest account credentials and even pics of IDs.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-4629 β€Ό

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.

πŸ“– Read

via "National Vulnerability Database".
🦿 Account takeover fraud rates skyrocketed 282% over last year 🦿

ATO is the weapon of choice for fraudsters leading up to the holiday shopping season, new data from Sift shows, and consumers place account security burden on businesses.

πŸ“– Read

via "Tech Republic".
πŸ•΄ COVID-19 Creates Opening for OT Security Reform πŸ•΄

Operations technology was once considered low risk, at least until the virus came along and re-arranged the threat landscape.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Phishing Attack Targets Microsoft 365 Users With Netflix & Amazon Lures πŸ•΄

Cyberattacker TA2552 primarily targets Spanish speakers with messages that leverage a narrow range of themes and popular brands.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-12506 β€Ό

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362 version FW03 and prior versions. WAGO 750-363 version FW03 and prior versions. WAGO 750-823 version FW03 and prior versions. WAGO 750-832/xxx-xxx version FW03 and prior versions. WAGO 750-862 version FW03 and prior versions. WAGO 750-891 version FW03 and prior versions. WAGO 750-890/xxx-xxx version FW03 and prior versions.

πŸ“– Read

via "National Vulnerability Database".