πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Emotet Spoofs DNC In New Attack Campaign πŸ•΄

Thousands of Emotet emails contain a message body pulled directly from the Democratic National Committee website, researchers report.

πŸ“– Read

via "Dark Reading".
❌ Researchers Mixed on Sanctions for Ransomware Negotiators ❌

Financial institutions, cyber-insurance firms, and security firms have all been put on notice by the U.S. Department of the Treasury.

πŸ“– Read

via "Threat Post".
🦿 Vulnerable supply chains introduce increasingly interconnected attack surfaces 🦿

Accenture Security lists five other "extreme but plausible threat scenarios in financial services" in a new report.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-5422 β€Ό

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Bing.com Hostname / IP Enumerator 1.0.4 πŸ› 

This tool enumerates hostnames from Bing.com for an IP address. Bing.com is Microsoft's search engine which has an IP: search parameter. Written in Bash for Linux. Requires wget.

πŸ“– Read

via "Packet Storm Security".
❌ Account Takeover Fraud Losses Total Billions Across Online Retailers ❌

Account takeover fraud (ATO) attacks are on the rise, up nearly 300 percent since last year.

πŸ“– Read

via "Threat Post".
❌ Voter Registration β€˜Error’ Phish Hits During U.S. Election Frenzy ❌

Phishing emails tell recipients that their voter's registration applications are incomplete - but instead steal their social security numbers, license data and more.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-24568 β€Ό

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrary information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24627 β€Ό

A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5979 β€Ό

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which a user is presented with a dialog box for input by a high-privilege process, which may lead to escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Biometric Data Collection Demands Scrutiny of Privacy Law πŸ•΄

An IT lawyer digs into the implications of collecting biometric data, why it can't be anonymized, and what nations are doing about it.

πŸ“– Read

via "Dark Reading".
❌ Egregor Ransomware Threatens β€˜Mass-Media’ Release of Corporate Data ❌

The newly discovered ransomware is hitting companies worldwide, including the GEFCO global logistics company.

πŸ“– Read

via "Threat Post".
πŸ•΄ Researchers Adapt AI With Aim to Identify Anonymous Authors πŸ•΄

At Black Hat Asia, artificial intelligence and cybersecurity researchers use neural networks to attempt to identify authors, but accuracy is still wanting.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-5984 β€Ό

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which it may have the use-after-free vulnerability while freeing some resources, which may lead to denial of service, code execution, and information disclosure. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-15231 β€Ό

In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26526 β€Ό

An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25776 β€Ό

Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an attacker could exploit a critical file on the system to escalate their privileges. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-18924 β€Ό

** DISPUTED ** oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the claim in the Readme of "RFC 6749 compliant" is valid and not misleading and I also therefore wouldn't describe this as a "vulnerability" with the library per se.'

πŸ“– Read

via "National Vulnerability Database".
⚠ Serious Security: Phishing without links – when phishers bring along their own web pages ⚠

How do you "check the URL before you click" if the web page you're visiting is already on your own computer?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-7709 β€Ό

This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.

πŸ“– Read

via "National Vulnerability Database".