๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.9K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด COVID-19: Latest Security News & Commentary ๐Ÿ•ด

Check out Dark Reading's updated, exclusive news and commentary surrounding the coronavirus pandemic.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2020-3998 โ€ผ

VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the client crashes.

๐Ÿ“– Read

via "National Vulnerability Database".
โŒ COVID-19 Vaccine-Maker Hit with Cyberattack, Data Breach โŒ

Dr. Reddy's, the contractor for Russiaโ€™s โ€œSputinik Vโ€ COVID-19 vaccine and a major generics producer, has had to close plants and isolate its data centers.

๐Ÿ“– Read

via "Threat Post".
๐Ÿฆฟ 75% of all 56 US states and territories show signs of vulnerable election IT infrastructure, report finds ๐Ÿฆฟ

The report comes as officials in Georgia revealed more information about a ransomware attack that affected a digital voter database.

๐Ÿ“– Read

via "Tech Republic".
โŒ Georgia Election Data Hit in Ransomware Attack โŒ

With Election Day approaching, local governments need to be prepared for malware attacks on election infrastructure.

๐Ÿ“– Read

via "Threat Post".
โŒ Election Security: Beyond Mail-In Voting โŒ

There are many areas of the election process that criminal hackers can target to influence election results.

๐Ÿ“– Read

via "Threat Post".
โŒ Louisiana Calls Out National Guard to Fight Ransomware Surge โŒ

An investigation showed a custom backdoor RAT and the Emotet trojan in the networks of municipal victims of the attacks.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด Flurry of Warnings Highlight Cyber Threats to US Elections ๐Ÿ•ด

FBI and intelligence officials issue fresh warnings about election interference attempts by Iranian and Russian threat actors.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2020-25483 โ€ผ

An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-24848 โ€ผ

FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain complete persistent access to the local system.

๐Ÿ“– Read

via "National Vulnerability Database".
โŒ IoT Device Takeovers Surge 100 Percent in 2020 โŒ

The COVID-19 pandemic, coupled with an explosion in the number of connected devices, have led to a swelling in IoT infections observed on wireless networks.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด Cybercriminals Could be Coming After Your Coffee ๐Ÿ•ด

Researchers show no IoT device is too small to fall victim to ransomware techniques.

๐Ÿ“– Read

via "Dark Reading".
โŒ U.S. Levies Sanctions Against Russian Research Institution Linked to Triton Malware โŒ

The latest in a flurry of actions this week, tied to foreign threats against U.S. computer systems, includes sanctions by the Department of the Treasury.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด US Treasury Sanctions Russian Institution Linked to Triton Malware ๐Ÿ•ด

Triton, also known as TRISIS and HatMan, was developed to target and manipulate industrial control systems, the US Treasury reports.

๐Ÿ“– Read

via "Dark Reading".
โš  Naked Security Live โ€“ Whoโ€™s watching you? 5 mobile privacy tips โš 

Here's the latest Naked Security Live video - enjoy (and please share with your friends)!

๐Ÿ“– Read

via "Naked Security".
โ€ผ CVE-2020-27388 โ€ผ

Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-27388 โ€ผ

Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด The Story of McAfee: How the Security Giant Arrived at a Second IPO ๐Ÿ•ด

Industry watchers explore the story of McAfee, from its founding in 1987, to its spinoff from Intel, to how it's keeping up with competitors.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2020-27678 โ€ผ

An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-7751 โ€ผ

This affects all versions of package pathval.

๐Ÿ“– Read

via "National Vulnerability Database".