πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-9486 β€Ό

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26524 β€Ό

CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26538 β€Ό

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.

πŸ“– Read

via "National Vulnerability Database".
⚠ Serious Security: Phishing without links – when phishers bring along their own web pages ⚠

How do you "check the URL before you click" if the web page you're visiting is already on your own computer?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-7737 β€Ό

All versions of package safetydance are vulnerable to Prototype Pollution via the set function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7736 β€Ό

The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-8110 β€Ό

A vulnerability has been discovered in the ceva_emu.cvd module that results from a lack of proper validation of user-supplied data, which can result in a pointer that is fetched from uninitialized memory. This can lead to denial-of-service. This issue affects: Bitdefender Engines version 7.84897 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 10/2 πŸ”

A legal right to work from home, insensitive phishing, and election disinformation - catch up on the week's news with the Friday Five!

πŸ“– Read

via "Digital Guardian".
❌ 305 CVEs and Counting: Bug-Hunting Stories From a Security Engineer ❌

Larry Cashdollar, senior security response engineer at Akamai, talks about the craziest stories he's faced, reporting CVEs since 1994.

πŸ“– Read

via "Threat Post".
πŸ•΄ Truncated URLs Look to Make Big Dent in Phishing πŸ•΄

The approach is a long time in coming and will test the premise that users can more easily detect a suspicious domain from the name alone.

πŸ“– Read

via "Dark Reading".
🦿 Report: Despite more cyberthreats during COVID-19, most businesses confident about cybersecurity 🦿

Remote working and phishing attacks spiked during the coronavirus pandemic, but organizations believe they're on track with their cybersecurity plans, according to a new report from CompTIA.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 3 Months for the Cybercrime Books πŸ•΄

From July through September, US law enforcement handed down major indictments or sanctions against foreign threat groups at least six times.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-25623 β€Ό

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.

πŸ“– Read

via "National Vulnerability Database".
❌ Years-Long β€˜SilentFade’ Attack Drained Facebook Victims of $4M ❌

Facebook detailed an ad-fraud cyberattack that's been ongoing since 2016, stealing Facebook credentials and browser cookies.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-7069 β€Ό

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.

πŸ“– Read

via "National Vulnerability Database".
❌ LatAm Banking Trojans Collaborate in Never-Before-Seen Effort ❌

Eleven different malware families are coordinating on distribution, features, geo-targeting and more.

πŸ“– Read

via "Threat Post".
πŸ•΄ Name That Toon: Castle in the Sky πŸ•΄

Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Emotet Spoofs DNC In New Attack Campaign πŸ•΄

Thousands of Emotet emails contain a message body pulled directly from the Democratic National Committee website, researchers report.

πŸ“– Read

via "Dark Reading".
❌ Researchers Mixed on Sanctions for Ransomware Negotiators ❌

Financial institutions, cyber-insurance firms, and security firms have all been put on notice by the U.S. Department of the Treasury.

πŸ“– Read

via "Threat Post".
🦿 Vulnerable supply chains introduce increasingly interconnected attack surfaces 🦿

Accenture Security lists five other "extreme but plausible threat scenarios in financial services" in a new report.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-5422 β€Ό

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

πŸ“– Read

via "National Vulnerability Database".