๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.9K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2020-12911 โ€ผ

A denial of service vulnerability exists in the D3DKMTCreateAllocation handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTCreateAllocation API request can cause an out-of-bounds read and denial of service (BSOD). This vulnerability can be triggered from a non-privileged account.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  Windows โ€œPing of Deathโ€ bug revealed โ€“ patch now! โš 

No one has figured out how to run code with this bug yet - but if they do, you can bet that someone will turn it into a computer worm.

๐Ÿ“– Read

via "Naked Security".
โ€ผ CVE-2020-7330 โ€ผ

Privilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call malicious software to execute with elevated privileges via editing of environment variables

๐Ÿ“– Read

via "National Vulnerability Database".
โŒ Cybercriminals Steal Nearly 1TB of Data from Miami-Based International Tech Firm โŒ

Databases of sensitive, financial and personally identifiable info and documents from Intcomex were leaked on Russian-language hacker forum after a ransomware attack.

๐Ÿ“– Read

via "Threat Post".
โŒ Google, Intel Warn on โ€˜Zero-Clickโ€™ Kernel Bug in Linux-Based IoT Devices โŒ

Intel and Google are urging users to update the Linux kernel to version 5.9 or later.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด NIST Quantum Cryptography Program Nears Completion ๐Ÿ•ด

The National Institute of Standards and Technology's first post-quantum cryptography standard will address key issues, approaches, an arms race, and the technology's uncertain future.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿฆฟ Survey finds that IT departments victimized by ransomware forever changed ๐Ÿฆฟ

IT managers at organizations hit by ransomware are nearly three times as likely to feel "significantly behind" when it comes to understanding cyberthreats, compared to their peers that have never been hit.

๐Ÿ“– Read

via "Tech Republic".
โ€ผ CVE-2020-6087 โ€ผ

An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability If the ANSI Extended Symbol Segment Sub-Type is supplied, the device treats the byte following as the Data Size in words. When this value represents a size greater than what remains in the packet data, the device enters a fault state where communication with the device is lost and a physical power cycle is required.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-6083 โ€ผ

An exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โŒ Intel Adds Memory Encryption, Firmware Security to Ice Lake Chips โŒ

Intel's addition of memory encryption to its upcoming 3rd generation Xeon Scalable processors matches AMD's Secure Memory Encryption (SME) feature.

๐Ÿ“– Read

via "Threat Post".
โ€ผ CVE-2020-0415 โ€ผ

In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of contact data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-156020795

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-0414 โ€ผ

In AudioFlinger::RecordThread::threadLoop of audioflinger/Threads.cpp, there is a possible non-silenced audio buffer due to a permissions bypass. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-157708122

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿฆฟ Zoom announces end-to-end encryption, customizable SDKs and more at Zoomtopia ๐Ÿฆฟ

Zoom's two-day online conference kicked off with a bevy of new product announcements around security and developer enhancements.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿฆฟ IoT security: University creates new labels for devices to increase awareness for consumers ๐Ÿฆฟ

What if you could compare security on IoT devices, similar to nutrition labels, before you buy them? One organization is trying to make that happen.

๐Ÿ“– Read

via "Tech Republic".
โŒ Silent Librarian Goes Back to School with Global Research-Stealing Effort โŒ

The Iranian hacker group is targeting universities in 12 countries.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด Intel's Ice Lake Beefs Up CPU Security for Cloud Workloads ๐Ÿ•ด

The third-generation Xeon processors build in hardware security features to provide extra protection to data in transit, at rest, and in use.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Assuring Business Continuity by Reducing Malware Dwell Time ๐Ÿ•ด

Here's how CISOs and IT security operations teams can best address key challenges to network monitoring that could increase malware dwell time.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2020-4395 โ€ผ

IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 179358.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ” Microsoft Fixes Critical TCP/IP Vulnerability ๐Ÿ”

A new, potentially wormable remote code execution vulnerability in the Windows TCP/IP stack was patched this week.

๐Ÿ“– Read

via "Digital Guardian".
โŒ Critical SonicWall VPN Portal Bug Allows DoS, Worming RCE โŒ

The CVE-2020-5135 stack-based buffer overflow security vulnerability is trivial to exploit, without logging in.

๐Ÿ“– Read

via "Threat Post".