πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-27642 β€Ό

A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27638 β€Ό

receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.

πŸ“– Read

via "National Vulnerability Database".
🦿 1Password for Linux desktop app now available in beta 🦿

A full Linux version of the popular password manager is expected early next year.

πŸ“– Read

via "Tech Republic".
πŸ•΄ McAfee Raises $740M in Second IPO πŸ•΄

The security software giant and its investors sold 37 million shares priced at $20 each, putting McAfee's value around $8.6 billion.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-26650 β€Ό

AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27646 β€Ό

Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.

πŸ“– Read

via "National Vulnerability Database".
❌ Chrome 86 Aims to Bar Abusive Notification Content ❌

Google said Chrome 86 will automatically block malicious notifications that may be used for phishing or malware.

πŸ“– Read

via "Threat Post".
❌ Facebook, News and XSS Underpin Complex Browser Locker Attack ❌

A sophisticated β€œbrowser locker” campaign is spreading via Facebook, ultimately pushing a tech-support scam. The effort is more advanced than most, because it involves exploiting a cross-site scripting (XSS) vulnerability on a popular news site, researchers said. Browser lockers are a type of redirection attack where web surfers will click on a site, only to […]

πŸ“– Read

via "Threat Post".
πŸ•΄ To Err Is Human: Misconfigurations & Employee Neglect Are a Fact of Life πŸ•΄

The cyber kill chain is only as strong as its weakest link, so organizations should reinforce that link with a properly equipped dedicated security team.

πŸ“– Read

via "Dark Reading".
πŸ” Former Employee Breached Company Payroll Data πŸ”

Before resigning, the employee stole company data and created a "superuser" account that let him access the network after he left.

πŸ“– Read

via "Digital Guardian".
β€Ό CVE-2020-27195 β€Ό

HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6

πŸ“– Read

via "National Vulnerability Database".
❌ Researcher: I Hacked Trump’s Twitter by Guessing Password ❌

Trump’s weak Twitter password and lack of basic two-factor authentication protections made it shockingly simple to hack his account, Dutch security researcher Victor Gevers reported.  

πŸ“– Read

via "Threat Post".
πŸ•΄ 8 New and Hot Cybersecurity Certifications for 2020 πŸ•΄

While the usual security certs remain popular, interest in privacy skills and cloud experience are pushing new credentials into the market.

πŸ“– Read

via "Dark Reading".
πŸ•΄ WordPress Plug-in Updated in Rare Forced Action πŸ•΄

The Logonizer login security plug-in was automatically updated to patch a SQL injection vulnerability.

πŸ“– Read

via "Dark Reading".
🦿 How to create a new user with admin privileges on Linux 🦿

Adding a user with admin privileges on Linux is easier than you think. Jack Wallen shows you how.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-27664 β€Ό

admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-9900 β€Ό

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A local attacker may be able to elevate their privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-9990 β€Ό

A race condition was addressed with additional validation. This issue is fixed in macOS Catalina 10.15.6. A malicious application may be able to execute arbitrary code with kernel privileges.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Credential-Stuffing Attacks Plague Loyalty Programs πŸ•΄

But that's not the only type of web attack cybercriminals have been profiting from.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 7 Mobile Browsers Vulnerable to Address-Bar Spoofing πŸ•΄

Flaws allow attackers to manipulate URLs users see on their mobile devices, Rapid7 says

πŸ“– Read

via "Dark Reading".
πŸ•΄ Botnet Infects Hundreds of Thousands of Websites πŸ•΄

KashmirBlack has been targeting popular content management systems, such as WordPress, Joomla, and Drupal, and using Dropbox and GitHub for communication to hide its presence.

πŸ“– Read

via "Dark Reading".