πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-7751 β€Ό

This affects all versions of package pathval.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft's Kubernetes Threat Matrix: Here's What's Missing πŸ•΄

With a fuller picture of the Kubernetes threat matrix, security teams can begin to implement mitigation strategies to protect their cluster from threats.

πŸ“– Read

via "Dark Reading".
❌ Nando’s Hackers Feast on Customer Accounts ❌

Multiple chicken diners said their usernames and passwords were stolen and the accounts used to place high-volume orders.

πŸ“– Read

via "Threat Post".
❌ Vastaamo Breach: Hackers Blackmailing Psychotherapy Patients ❌

Cybercriminals have already reportedly posted the details of 300 Vastaamo patients - and are threatening to release the data of others unless a ransom is paid.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-25470 β€Ό

AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can lead to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Sifter 10.5f πŸ› 

Sifter is a osint, recon, and vulnerability scanner. It combines a plethora of tools within different module sets in order to quickly perform recon tasks, check network firewalling, enumerate remote and local hosts, and scan for the blue vulnerabilities within Microsoft systems and if unpatched, exploits them.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Teach Your Employees Well: How to Spot Smishing & Vishing Scams πŸ•΄

One of the best ways to keep employees from falling victim to these social-engineering attacks is to teach them the signs.

πŸ“– Read

via "Dark Reading".
❌ Containerd Bug Exposes Cloud Account Credentials ❌

The flaw (CVE-2020-15157) is located in the container image-pulling process.

πŸ“– Read

via "Threat Post".
πŸ•΄ New Report Links Cybersecurity and Sustainability πŸ•΄

Some have also created the role of chief sustainability officer, according to Kaspersky.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-7126 β€Ό

A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7196 β€Ό

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7752 β€Ό

This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.

πŸ“– Read

via "National Vulnerability Database".
❌ β€˜Among Us’ Mobile Game Under Siege by Attackers ❌

Ongoing attacks on the wildly popular game Among Us are testing developers’ ability to keep up.

πŸ“– Read

via "Threat Post".
🦿 Enterprises confident Chief Sustainability Officer (CSO) will improve cybersecurity 🦿

98% of enterprises want CSOs, but 56% of industrial businesses don't have plans to introduce one to their company, according to a new Kaspersky report.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2017-18925 β€Ό

opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26566 β€Ό

A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a webu.c segmentation fault and kill the main process via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26161 β€Ό

In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Former Healthcare Exec Sentenced for Sabotaging COVID-19 Supply Deliveries πŸ”

The ex-VP conducted an intrusion into his former employer’s package shipping system and delayed PPE essential to healthcare workers.

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Cybercriminals Extort Psychotherapy Patients Following Vastaamo Breach πŸ•΄

An attacker is running a Tor site to leak the session notes of 300 patients at Vastaamo, a Finnish psychotherapy facility.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-1915 β€Ό

An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft IE Browser Death March Hastens ❌

Internet Explorer redirects more traffic to Edge Chromium browser as Microsoft warns of the upcoming demise of the once dominant browser.

πŸ“– Read

via "Threat Post".