πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ IRS COVID-19 Relief Payment Deadlines Anchor Convincing Phish ❌

The upcoming deadlines for applying for coronavirus relief are the lure for a phish that gets around email security gateways by using a legitimate SharePoint page for data-harvesting.

πŸ“– Read

via "Threat Post".
🦿 Okta opens the door to third-party developers with new Okta Devices SDK and API 🦿

The new platform will allow developers to leverage Okta's SSO technology to build branded biometric authentication for iOS and Android apps.

πŸ“– Read

via "Tech Republic".
🦿 Security firm: WarezTheRemote flaw could turn a Comcast remote into a listening device 🦿

Could your cable TV device spy on you? Vulnerability found and patched in Comcast TV remote.

πŸ“– Read

via "Tech Republic".
❌ PoetRAT Resurfaces in Attacks in Azerbaijan Amid Escalating Conflict ❌

Spear-phishing attacks targeting VIPs and others show key malware changes and are likely linked to the current conflict with Armenia.

πŸ“– Read

via "Threat Post".
πŸ•΄ What the Sci-Fi Hit Altered Carbon Teaches Us About Virtualization Security πŸ•΄

The Netflix show may be fantastical, but it has real-world lessons about virtualization.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-25985 β€Ό

MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserver (php files can be unlinked and not deleted).

πŸ“– Read

via "National Vulnerability Database".
🦿 Phishing attack spoofs IRS COVID-19 relief to steal personal data 🦿

The phishing page tries to obtain email credentials, Social Security numbers, driver's license numbers, and tax numbers, says Armorblox.

πŸ“– Read

via "Tech Republic".
❌ Google’s Chrome 86: Critical Payments Bug, Password Checker Among Security Notables ❌

Google is rolling out 35 security fixes, and a new password feature, in Chrome 86 versions for Windows, Mac, Android and iOS users.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-13332 β€Ό

Improper access expiration date validation in GitLab version >=8.11.0-rc6+ allows user to have access to projects with expiration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13346 β€Ό

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14355 β€Ό

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Packet Fence 10.2.0 πŸ› 

PacketFence is a network access control (NAC) system. It is actively maintained and has been deployed in numerous large-scale institutions. It can be used to effectively secure networks, from small to very large heterogeneous networks. PacketFence provides NAC-oriented features such as registration of new network devices, detection of abnormal network activities including from remote snort sensors, isolation of problematic devices, remediation through a captive portal, and registration-based and scheduled vulnerability scans.

πŸ“– Read

via "Packet Storm Security".
πŸ” FINRA Warns Financial Services Firms of New Phishing Campaign πŸ”

FINRA, a self-regulatory organization that oversees brokers and broker-dealers, is warning about a new phishing attack that looks like its coming from the organization.

πŸ“– Read

via "Digital Guardian".
❌ BAHAMUT Spies-for-Hire Linked to Extensive Nation-State Activity ❌

Researchers uncovered a sophisticated, incredibly well-resourced APT that has its fingers in wide-ranging espionage and disinformation campaigns.

πŸ“– Read

via "Threat Post".
πŸ•΄ The New War Room: Cybersecurity in the Modern Era πŸ•΄

The introduction of the virtual war room is a new but necessary shift. To ensure its success, security teams must implement new systems and a new approach to cybersecurity.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2019-16160 β€Ό

An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthenticated attackers to crash the service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26870 β€Ό

Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.

πŸ“– Read

via "National Vulnerability Database".
❌ Google Rolls Out Fixes for High-Severity Android System Flaws ❌

The most serious bugs are elevation-of-privilege issues in the Android System component (CVE-2020-0215 and CVE-2020-0416).

πŸ“– Read

via "Threat Post".
πŸ•΄ CISA Warns of Renewed Emotet Activity πŸ•΄

The Emotet malware dropper is seeing an upsurge in new activity in the second half of 2020.

πŸ“– Read

via "Dark Reading".
❌ Feds Sound Alarm Over Emotet Attacks on State, Local Govs ❌

CISA warned already-strained public-sector entities about disturbing spikes in Emotet phishing attacks aimed at municipalities.

πŸ“– Read

via "Threat Post".
🦿 3 ways criminals use artificial intelligence in cybersecurity attacks 🦿

Bad actors use machine learning to break passwords more quickly and build malware that knows how to hide, experts warn.

πŸ“– Read

via "Tech Republic".