🦿 Account takeover fraud rates skyrocketed 282% over last year 🦿
📖 Read
via "Tech Republic".
ATO is the weapon of choice for fraudsters leading up to the holiday shopping season, new data from Sift shows, and consumers place account security burden on businesses.📖 Read
via "Tech Republic".
TechRepublic
Account takeover fraud rates skyrocketed 282% over last year
ATO is the weapon of choice for fraudsters leading up to the holiday shopping season, new data from Sift shows, and consumers place account security burden on businesses.
🕴 COVID-19 Creates Opening for OT Security Reform 🕴
📖 Read
via "Dark Reading".
Operations technology was once considered low risk, at least until the virus came along and re-arranged the threat landscape.📖 Read
via "Dark Reading".
Dark Reading
COVID-19 Creates Opening for OT Security Reform
Operations technology was once considered low risk, at least until the virus came along and re-arranged the threat landscape.
🕴 Phishing Attack Targets Microsoft 365 Users With Netflix & Amazon Lures 🕴
📖 Read
via "Dark Reading".
Cyberattacker TA2552 primarily targets Spanish speakers with messages that leverage a narrow range of themes and popular brands.📖 Read
via "Dark Reading".
Dark Reading
Vulnerabilities & Threats recent news | Dark Reading
Explore the latest news and expert commentary on Vulnerabilities & Threats, brought to you by the editors of Dark Reading
‼ CVE-2020-12506 ‼
📖 Read
via "National Vulnerability Database".
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362 version FW03 and prior versions. WAGO 750-363 version FW03 and prior versions. WAGO 750-823 version FW03 and prior versions. WAGO 750-832/xxx-xxx version FW03 and prior versions. WAGO 750-862 version FW03 and prior versions. WAGO 750-891 version FW03 and prior versions. WAGO 750-890/xxx-xxx version FW03 and prior versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-12505 ‼
📖 Read
via "National Vulnerability Database".
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852 version FW07 and prior versions. WAGO 750-880/xxx-xxx version FW07 and prior versions. WAGO 750-881 version FW07 and prior versions. WAGO 750-831/xxx-xxx version FW07 and prior versions. WAGO 750-882 version FW07 and prior versions. WAGO 750-885/xxx-xxx version FW07 and prior versions. WAGO 750-889 version FW07 and prior versions.📖 Read
via "National Vulnerability Database".
🔏 Insider Stole Yacht IP via USB, Company Alleges 🔏
📖 Read
via "Digital Guardian".
The latest industrial espionage case involves theft at a yacht manufacturer by a now ex-employee.📖 Read
via "Digital Guardian".
Digital Guardian
Insider Stole Yacht IP via USB, Company Alleges
The latest industrial espionage case involves theft at a yacht manufacturer by a now ex-employee.
❌ Android Spyware Variant Snoops on WhatsApp, Telegram Messages ❌
📖 Read
via "Threat Post".
The Android malware comes from threat group APT-C-23, also known as Two-Tailed Scorpion and Desert Scorpion.📖 Read
via "Threat Post".
Threat Post
Android Spyware Variant Snoops on WhatsApp, Telegram Messages
The Android malware comes from threat group APT-C-23, also known as Two-Tailed Scorpion and Desert Scorpion.
🕴 A Guide to the NIST Cybersecurity Framework 🕴
📖 Read
via "Dark Reading".
With cybersecurity threats growing exponentially, it has never been more important to put together an efficient cyber-risk management policy, and NIST's framework can help.📖 Read
via "Dark Reading".
Dark Reading
A Guide to the NIST Cybersecurity Framework
With cybersecurity threats growing exponentially, it has never been more important to put together an efficient cyber-risk management policy, and NIST's framework can help.
‼ CVE-2019-20921 ‼
📖 Read
via "National Vulnerability Database".
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-21523 ‼
📖 Read
via "National Vulnerability Database".
A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign test="freemarker.template.utility.Execute"?new()> ${test("touch /tmp/freemarkerPwned")}📖 Read
via "National Vulnerability Database".
‼ CVE-2020-21527 ‼
📖 Read
via "National Vulnerability Database".
There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, when deleting their backup files, to delete any files on the system through directory traversal.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-21244 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-25763 ‼
📖 Read
via "National Vulnerability Database".
Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-26157 ‼
📖 Read
via "National Vulnerability Database".
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.📖 Read
via "National Vulnerability Database".
🕴 What Legal Language Should I Look Out for When Selecting Cyber Insurance? 🕴
📖 Read
via "Dark Reading".
At times, vague coverage can actually work for you.📖 Read
via "Dark Reading".
Dark Reading
What Legal Language Should I Look Out for When Selecting Cyber Insurance?
At times, vague coverage can actually work for you.
❌ OAuth Consent Phishing Ramps Up with Microsoft Office 365 Attacks ❌
📖 Read
via "Threat Post".
Attackers gain read-only permissions to snoop around Office 365 accounts, including emails, contacts and more.📖 Read
via "Threat Post".
Threat Post
OAuth Consent Phishing Ramps Up with Microsoft Office 365 Attacks
Attackers gain read-only permissions to snoop around Office 365 accounts, including emails, contacts and more.
🕴 Cloud Misconfiguration Mishaps Businesses Must Watch 🕴
📖 Read
via "Dark Reading".
Cloud security experts explain which misconfigurations are most common and highlight other areas of the cloud likely to threaten businesses.📖 Read
via "Dark Reading".
Dark Reading
Cloud Misconfiguration Mishaps Businesses Must Watch
Cloud security experts explain which misconfigurations are most common and highlight other areas of the cloud likely to threaten businesses.
🕴 GitHub Tool Spots Security Vulnerabilities in Code 🕴
📖 Read
via "Dark Reading".
Scanner, which just became generally available, lets developers spot problems before code gets into production.📖 Read
via "Dark Reading".
Dark Reading
GitHub Tool Spots Security Vulnerabilities in Code
Scanner, which just became generally available, lets developers spot problems before code gets into production.
‼ CVE-2020-25781 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-25816 ‼
📖 Read
via "National Vulnerability Database".
HashiCorp Vault and Vault Enterprise 1.0 before 1.5.4 have Incorrect Access Control.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-13336 ‼
📖 Read
via "National Vulnerability Database".
An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.📖 Read
via "National Vulnerability Database".