πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 How to boost the effectiveness of your cybersecurity operations 🦿

Data breaches occur despite tight security. Arctic Wolf explains how to increase your security effectiveness.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 10 Years Since Stuxnet: Is Your Operational Technology Safe? πŸ•΄

The destructive worm may have debuted a decade ago, but Stuxnet is still making its presence known. Here are steps you can take to stay safer from similar attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-26582 β€Ό

D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value for ping (aka res_config_action=3&res_config_id=18).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-4725 β€Ό

IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172131.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Google Brings Password Protection to iOS, Android in Chrome 86 πŸ•΄

Chrome 86 will alert users when stored passwords are compromised, and block or warn of insecure downloads, among other security updates.

πŸ“– Read

via "Dark Reading".
❌ Male Chastity Device Comes with Massive Security Flaws ❌

Smart sex toy vulnerable to hacks, researchers say -- which could expose users’ most sensitive bits (of data) to cybercriminals.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-26598 β€Ό

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management component could allow an unauthorized actor to kill a TCP connection. The LG ID is LVE-SMP-200023 (October 2020).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-15239 β€Ό

In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data` suffix and which are accompanied by a JSON file with the `.meta` suffix. This can lead to Information Disclosure and in some shared-hosting scenarios also to circumvention of authentication or other limitations on the outbound (GET) traffic. For example, in a scenario where a single server has multiple instances of the application running (with separate DATA_ROOT settings), an attacker who has knowledge about the directory structure is able to read files from any other instance to which the process has read access. If instances have individual authentication (for example, HTTP authentication via a reverse proxy, source IP based filtering) or other restrictions (such as quotas), attackers may circumvent those limits in such a scenario by using the Directory Traversal to retrieve data from the other instances. If the associated XMPP server (or anyone knowing the SECRET_KEY) is malicious, they can write files outside the DATA_ROOT. The files which are written are constrained to have the `.meta` and the `.data` suffixes; the `.meta` file will contain the JSON with the Content-Type of the original request and the `.data` file will contain the payload. The issue is patched in version 0.4.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ New Research Finds Bugs in Every Anti-Malware Product Tested πŸ•΄

Products from every vendor had issues that allowed attackers to elevate privileges on a system -- if they already were on it.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zerologon Vulnerability Used in APT Attacks πŸ•΄

MERCURY, the Iranian advanced persistent threat group, is using Zerologon in a new series of attacks detected by Microsoft.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-14183 β€Ό

Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before 8.12.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance πŸ•΄

Too many organizations fail to enact the baseline payment security controls, according to the Verizon 2020 Payment Security Report, and the recent Blackbaud ransomware incident is merely the latest evidence.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-7742 β€Ό

This affects the package simpl-schema before 1.10.2.

πŸ“– Read

via "National Vulnerability Database".
❌ Comcast TV Remote Hack Opens Homes to Snooping ❌

Researchers disclosed the 'WarezTheRemote' attack, affecting Comcast's XR11 voice remote control.

πŸ“– Read

via "Threat Post".
❌ IRS COVID-19 Relief Payment Deadlines Anchor Convincing Phish ❌

The upcoming deadlines for applying for coronavirus relief are the lure for a phish that gets around email security gateways by using a legitimate SharePoint page for data-harvesting.

πŸ“– Read

via "Threat Post".
🦿 Okta opens the door to third-party developers with new Okta Devices SDK and API 🦿

The new platform will allow developers to leverage Okta's SSO technology to build branded biometric authentication for iOS and Android apps.

πŸ“– Read

via "Tech Republic".
🦿 Security firm: WarezTheRemote flaw could turn a Comcast remote into a listening device 🦿

Could your cable TV device spy on you? Vulnerability found and patched in Comcast TV remote.

πŸ“– Read

via "Tech Republic".
❌ PoetRAT Resurfaces in Attacks in Azerbaijan Amid Escalating Conflict ❌

Spear-phishing attacks targeting VIPs and others show key malware changes and are likely linked to the current conflict with Armenia.

πŸ“– Read

via "Threat Post".
πŸ•΄ What the Sci-Fi Hit Altered Carbon Teaches Us About Virtualization Security πŸ•΄

The Netflix show may be fantastical, but it has real-world lessons about virtualization.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-25985 β€Ό

MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserver (php files can be unlinked and not deleted).

πŸ“– Read

via "National Vulnerability Database".
🦿 Phishing attack spoofs IRS COVID-19 relief to steal personal data 🦿

The phishing page tries to obtain email credentials, Social Security numbers, driver's license numbers, and tax numbers, says Armorblox.

πŸ“– Read

via "Tech Republic".