π΄ FIRST Announces Cyber-Response Ethical Guidelines π΄
π Read
via "Dark Reading".
The 12 points seek to provide security professionals with advice on ethical behavior during incident response.π Read
via "Dark Reading".
Dark Reading
FIRST Announces Cyber-Response Ethical Guidelines
The 12 points seek to provide security professionals with advice on ethical behavior during incident response.
βΌ CVE-2020-27615 βΌ
π Read
via "National Vulnerability Database".
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.π Read
via "National Vulnerability Database".
βΌ CVE-2020-9749 βΌ
π Read
via "National Vulnerability Database".
Adobe Animate version 20.5 (and earlier) is affected by an out-of-bounds read vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .fla file in Animate.π Read
via "National Vulnerability Database".
βΌ CVE-2020-24421 βΌ
π Read
via "National Vulnerability Database".
Adobe InDesign version 15.1.2 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .indd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2020-17355 βΌ
π Read
via "National Vulnerability Database".
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27619 βΌ
π Read
via "National Vulnerability Database".
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27620 βΌ
π Read
via "National Vulnerability Database".
The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.π Read
via "National Vulnerability Database".
β Time for a mobile privacy reset? β
π Read
via "Naked Security".
Can you remember which permissions you gave to what apps, and why? Nor can we... time for a reset!π Read
via "Naked Security".
Naked Security
iOS 14 and Android 11 privacy tips β top 5 things to check
Can you remember which permissions you gave to what apps, and why? Nor can we⦠time for a reset!
π΄ Implementing Proactive Cyber Controls in OT: Myths vs. Reality π΄
π Read
via "Dark Reading".
Debunking the myths surrounding the implementation of proactive cyber controls in operational technology.π Read
via "Dark Reading".
Dark Reading
Implementing Proactive Cyber Controls in OT: Myths vs. Reality
Debunking the myths surrounding the implementation of proactive cyber controls in operational technology.
β Feds: Iran Behind βProud Boysβ Email Attacks on Democratic Voters β
π Read
via "Threat Post".
Messages that threaten people to βvote for Trump or elseβ are part of foreign adversariesβ attempts to interfere with the Nov. 3 election, according to feds.π Read
via "Threat Post".
Threat Post
Feds: Iran Behind βProud Boysβ Email Attacks on Democratic Voters
Messages that threaten people to βvote for Trump or elseβ are part of foreign adversariesβ attempts to interfere with the Nov. 3 election, according to feds.
π΄ Need for 'Guardrails' in Cloud-Native Applications Intensifies π΄
π Read
via "Dark Reading".
With more organizations shifting to cloud services in the pandemic, experts say the traditionally manual process of securing them will be replaced by automated tools in 2021 and beyond.π Read
via "Dark Reading".
Dark Reading
Need for 'Guardrails' in Cloud-Native Applications Intensifies
With more organizations shifting to cloud services in the pandemic, experts say the traditionally manual process of securing them will be replaced by automated tools in 2021 and beyond.
βΌ CVE-2020-27642 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27638 βΌ
π Read
via "National Vulnerability Database".
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.π Read
via "National Vulnerability Database".
π¦Ώ 1Password for Linux desktop app now available in beta π¦Ώ
π Read
via "Tech Republic".
A full Linux version of the popular password manager is expected early next year.π Read
via "Tech Republic".
TechRepublic
1Password for Linux desktop app now available in beta
A full Linux version of the popular password manager is expected early next year.
π΄ McAfee Raises $740M in Second IPO π΄
π Read
via "Dark Reading".
The security software giant and its investors sold 37 million shares priced at $20 each, putting McAfee's value around $8.6 billion.π Read
via "Dark Reading".
Dark Reading
McAfee Raises $740M in Second IPO
The security software giant and its investors sold 37 million shares priced at $20 each, putting McAfee's value around $8.6 billion.
βΌ CVE-2020-26650 βΌ
π Read
via "National Vulnerability Database".
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.phpπ Read
via "National Vulnerability Database".
βΌ CVE-2020-27646 βΌ
π Read
via "National Vulnerability Database".
Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.π Read
via "National Vulnerability Database".
β Chrome 86 Aims to Bar Abusive Notification Content β
π Read
via "Threat Post".
Google said Chrome 86 will automatically block malicious notifications that may be used for phishing or malware.π Read
via "Threat Post".
Threat Post
Chrome 86 Aims to Bar Abusive Notification Content
Google said Chrome 86 will automatically block malicious notifications that may be used for phishing or malware.
β Facebook, News and XSS Underpin Complex Browser Locker Attack β
π Read
via "Threat Post".
A sophisticated βbrowser lockerβ campaign is spreading via Facebook, ultimately pushing a tech-support scam. The effort is more advanced than most, because it involves exploiting a cross-site scripting (XSS) vulnerability on a popular news site, researchers said. Browser lockers are a type of redirection attack where web surfers will click on a site, only to [β¦]π Read
via "Threat Post".
Threat Post
Facebook, News and XSS Underpin Complex Browser Locker Attack
An elaborate set of redirections and hundreds of URLs make up a wide-ranging tech-support scam.
π΄ To Err Is Human: Misconfigurations & Employee Neglect Are a Fact of Life π΄
π Read
via "Dark Reading".
The cyber kill chain is only as strong as its weakest link, so organizations should reinforce that link with a properly equipped dedicated security team.π Read
via "Dark Reading".
Dark Reading
To Err Is Human: Misconfigurations & Employee Neglect Are a Fact of Li
The cyber kill chain is only as strong as its weakest link, so organizations should reinforce that link with a properly equipped dedicated security team.
π Former Employee Breached Company Payroll Data π
π Read
via "Digital Guardian".
Before resigning, the employee stole company data and created a "superuser" account that let him access the network after he left.π Read
via "Digital Guardian".
Digital Guardian
Former Employee Breached Company Payroll Data
Before resigning, the employee stole company data and created a "superuser" account that let him access the network after he left.