πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-25781 β€Ό

An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25816 β€Ό

HashiCorp Vault and Vault Enterprise 1.0 before 1.5.4 have Incorrect Access Control.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13336 β€Ό

An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The No Good, Very Bad Week for Iran's Nation-State Hacking Ops πŸ•΄

A look at the state of Iran's cyber operations as the US puts the squeeze on it with a pile of indictments and sanctions.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2019-20902 β€Ό

Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20903 β€Ό

The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.

πŸ“– Read

via "National Vulnerability Database".
❌ InterPlanetary Storm Botnet Infects 13K Mac, Android Devices ❌

In addition to Windows and Linux machines, a new variant of the malware now targets Mac and Android devices.

πŸ“– Read

via "Threat Post".
⚠ #BeCyberSmart – why friends don’t let friends get scammed ⚠

Friends don't let friends get scammed. Because cybercrime hurts us all.

πŸ“– Read

via "Naked Security".
πŸ•΄ COVID-19: Latest Security News & Commentary πŸ•΄

Check out Dark Reading's updated, exclusive news and commentary surrounding the coronavirus pandemic.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cryptojacking: The Unseen Threat πŸ•΄

Mining malware ebbs and flows with the price of cryptocurrencies, and given the momentum on price is upward, cryptojacking is a very present threat.

πŸ“– Read

via "Dark Reading".
🦿 Cisco Talos researchers explain psychology behind election disinformation posts on social media 🦿

With the 2020 presidential election looming, here are questions to consider before posting on social media.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-8109 β€Ό

A vulnerability has been discovered in the ace.xmd parser that results from a lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. This can result in denial-of-service. This issue affects: Bitdefender Engines version 7.84892 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  WhatWeb Scanner 0.5.3 πŸ› 

WhatWeb is a next-generation web scanner. WhatWeb recognizes web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 1800 plugins, each to recognize something different. WhatWeb also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more. WhatWeb supports an aggression level to control the trade off between speed and reliability.

πŸ“– Read

via "Packet Storm Security".
πŸ‘1
❌ Spammers Smuggle LokiBot Via URL Obfuscation Tactic ❌

Researchers say that the campaign sidesteps end user detection and security solutions.

πŸ“– Read

via "Threat Post".
πŸ•΄ Russian National Sentenced to 7+ Years for Hacking US Tech Firms πŸ•΄

Yevgeniy Nikulin received an 88-month sentence for breaking into LinkedIn, Dropbox, and the now-defunct social platform Formspring.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-24860 β€Ό

CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.

πŸ“– Read

via "National Vulnerability Database".
❌ NFL, NBA Players Hacked in Would-Be Cyber-Slam-Dunk ❌

Federal prosecutors charged two men with crimes that carry up to 20 years in prison.

πŸ“– Read

via "Threat Post".
πŸ•΄ 'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness πŸ•΄

To protect your organization from all emerging file-borne threats, the security and leadership teams must align to develop a streamlined approach to file security.

πŸ“– Read

via "Dark Reading".
❌ Microsoft Office 365 Phishing Attack Uses Multiple CAPTCHAs ❌

Cybercriminals set up three different CAPTCHAs that Office 365 targets must click through before the final phishing page.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-16844 β€Ό

In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.

πŸ“– Read

via "National Vulnerability Database".