๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.9K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โŒ U.S. Levies Sanctions Against Russian Research Institution Linked to Triton Malware โŒ

The latest in a flurry of actions this week, tied to foreign threats against U.S. computer systems, includes sanctions by the Department of the Treasury.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด US Treasury Sanctions Russian Institution Linked to Triton Malware ๐Ÿ•ด

Triton, also known as TRISIS and HatMan, was developed to target and manipulate industrial control systems, the US Treasury reports.

๐Ÿ“– Read

via "Dark Reading".
โš  Naked Security Live โ€“ Whoโ€™s watching you? 5 mobile privacy tips โš 

Here's the latest Naked Security Live video - enjoy (and please share with your friends)!

๐Ÿ“– Read

via "Naked Security".
โ€ผ CVE-2020-27388 โ€ผ

Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-27388 โ€ผ

Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด The Story of McAfee: How the Security Giant Arrived at a Second IPO ๐Ÿ•ด

Industry watchers explore the story of McAfee, from its founding in 1987, to its spinoff from Intel, to how it's keeping up with competitors.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2020-27678 โ€ผ

An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-7751 โ€ผ

This affects all versions of package pathval.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Microsoft's Kubernetes Threat Matrix: Here's What's Missing ๐Ÿ•ด

With a fuller picture of the Kubernetes threat matrix, security teams can begin to implement mitigation strategies to protect their cluster from threats.

๐Ÿ“– Read

via "Dark Reading".
โŒ Nandoโ€™s Hackers Feast on Customer Accounts โŒ

Multiple chicken diners said their usernames and passwords were stolen and the accounts used to place high-volume orders.

๐Ÿ“– Read

via "Threat Post".
โŒ Vastaamo Breach: Hackers Blackmailing Psychotherapy Patients โŒ

Cybercriminals have already reportedly posted the details of 300 Vastaamo patients - and are threatening to release the data of others unless a ransom is paid.

๐Ÿ“– Read

via "Threat Post".
โ€ผ CVE-2020-25470 โ€ผ

AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can lead to remote code execution.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ›  Sifter 10.5f ๐Ÿ› 

Sifter is a osint, recon, and vulnerability scanner. It combines a plethora of tools within different module sets in order to quickly perform recon tasks, check network firewalling, enumerate remote and local hosts, and scan for the blue vulnerabilities within Microsoft systems and if unpatched, exploits them.

๐Ÿ“– Read

via "Packet Storm Security".
๐Ÿ•ด Teach Your Employees Well: How to Spot Smishing & Vishing Scams ๐Ÿ•ด

One of the best ways to keep employees from falling victim to these social-engineering attacks is to teach them the signs.

๐Ÿ“– Read

via "Dark Reading".
โŒ Containerd Bug Exposes Cloud Account Credentials โŒ

The flaw (CVE-2020-15157) is located in the container image-pulling process.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด New Report Links Cybersecurity and Sustainability ๐Ÿ•ด

Some have also created the role of chief sustainability officer, according to Kaspersky.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2020-7126 โ€ผ

A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-7196 โ€ผ

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-7752 โ€ผ

This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.

๐Ÿ“– Read

via "National Vulnerability Database".
โŒ โ€˜Among Usโ€™ Mobile Game Under Siege by Attackers โŒ

Ongoing attacks on the wildly popular game Among Us are testing developersโ€™ ability to keep up.

๐Ÿ“– Read

via "Threat Post".