🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Imperva Agrees to Buy jSonar 🕴

The deal is expected to close in mid-October.

📖 Read

via "Dark Reading".
🕴 CFAA 101: A Computer Fraud & Abuse Act Primer for InfoSec Pros 🕴

From WarGames, to Aaron Swartz, to bug bounties, to Van Buren, here's what cybersecurity researchers should know about the US's primary anti-hacking law before it gets its day in the Supreme Court.

📖 Read

via "Dark Reading".
🕴 US Treasury Warns of Sanctions Violations for Paying Ransomware Attackers 🕴

An alarming new advisory issued today by the federal government could upend ransomware response.

📖 Read

via "Dark Reading".
CVE-2020-15673

Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

📖 Read

via "National Vulnerability Database".
CVE-2020-15533

In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.

📖 Read

via "National Vulnerability Database".
QR Codes: A Sneaky Security Threat

What to watch out for, and how to protect yourself from malicious versions of these mobile shortcuts.

📖 Read

via "Threat Post".
🕴 New HP Bug Bounty Program Targets Vulns in Printer Cartridges 🕴

White-hat hackers will receive $10,000 for each security bug they discover plus a base fee, under this invitation-only initiative.

📖 Read

via "Dark Reading".
🕴 Singapore Asks Big Cybersecurity Questions to Improve National Defense 🕴

An executive from Singapore's Cyber Security Agency examines the role of security in a nation increasingly dependent on technology.

📖 Read

via "Dark Reading".
🦿 Cybersecurity best practices: An open letter to end users 🦿

In an effort to make IT pros' jobs easier, Jack Wallen offers cybersecurity tips to end users--in particular, what not to do to keep company networks, equipment, and data secure.

📖 Read

via "Tech Republic".
CVE-2020-5787

Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action.

📖 Read

via "National Vulnerability Database".
CVE-2020-5786

Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

📖 Read

via "National Vulnerability Database".
CVE-2020-9486

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

📖 Read

via "National Vulnerability Database".
CVE-2020-26524

CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.

📖 Read

via "National Vulnerability Database".
CVE-2020-26538

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.

📖 Read

via "National Vulnerability Database".
Serious Security: Phishing without links – when phishers bring along their own web pages

How do you "check the URL before you click" if the web page you're visiting is already on your own computer?

📖 Read

via "Naked Security".
CVE-2020-7737

All versions of package safetydance are vulnerable to Prototype Pollution via the set function.

📖 Read

via "National Vulnerability Database".
CVE-2020-7736

The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.

📖 Read

via "National Vulnerability Database".
CVE-2020-8110

A vulnerability has been discovered in the ceva_emu.cvd module that results from a lack of proper validation of user-supplied data, which can result in a pointer that is fetched from uninitialized memory. This can lead to denial-of-service. This issue affects: Bitdefender Engines version 7.84897 and prior versions.

📖 Read

via "National Vulnerability Database".
🔏 Friday Five 10/2 🔏

A legal right to work from home, insensitive phishing, and election disinformation - catch up on the week's news with the Friday Five!

📖 Read

via "Digital Guardian".
305 CVEs and Counting: Bug-Hunting Stories From a Security Engineer

Larry Cashdollar, senior security response engineer at Akamai, talks about the craziest stories he's faced, reporting CVEs since 1994.

📖 Read

via "Threat Post".
🕴 Truncated URLs Look to Make Big Dent in Phishing 🕴

The approach is a long time in coming and will test the premise that users can more easily detect a suspicious domain from the name alone.

📖 Read

via "Dark Reading".