πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-1915 β€Ό

An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft IE Browser Death March Hastens ❌

Internet Explorer redirects more traffic to Edge Chromium browser as Microsoft warns of the upcoming demise of the once dominant browser.

πŸ“– Read

via "Threat Post".
πŸ•΄ Neural Networks Help Users Pick More-Secure Passwords πŸ•΄

Typically, blocklists are used to prevent users from picking easily guessable patterns, but a small neural network can do the same job and suggests that complex password requirements are not necessary.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-27743 β€Ό

libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.

πŸ“– Read

via "National Vulnerability Database".
⚠ Phone scamming – friends don’t let friends get vished! ⚠

You probably back yourself not to be flattered or scared by a voice scammer - but what about vulnerable friends or relatives?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2018-21269 β€Ό

checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27180 β€Ό

konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7753 β€Ό

All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) [DNP] via trim().

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27182 β€Ό

Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, ixedit/editor_component.jsp, or the login form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27183 β€Ό

A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges of arbitrary user accounts, and have unspecified other impact.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-8956 β€Ό

Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.

πŸ“– Read

via "National Vulnerability Database".
❌ Google Boots 21 Bogus Gaming Apps from Play Marketplace ❌

Android apps packed with malware from HiddenAds family downloaded 8 million times from the online marketplace.

πŸ“– Read

via "Threat Post".
❌ Holiday Shopping Craze, COVID-19 Spur Retail Security Storm ❌

Veracode's Chris Eng discusses the cyber threats facing shoppers who are going online due to the pandemic and the imminent holiday season.

πŸ“– Read

via "Threat Post".
πŸ•΄ COVID-19: Latest Security News & Commentary πŸ•΄

Check out Dark Reading's updated, exclusive news and commentary surrounding the coronavirus pandemic.

πŸ“– Read

via "Dark Reading".
❌ Majority of Microsoft 365 Admins Don’t Enable MFA ❌

Beyond admins, researchers say that 97 percent of all total Microsoft 365 users do not use multi-factor authentication.

πŸ“– Read

via "Threat Post".
🦿 How foreign actors are trying to undermine the US presidential election 🦿

Through disinformation campaigns, foreign adversaries attempt to exploit the fear and uncertainty among US voters, says Digital Shadows.

πŸ“– Read

via "Tech Republic".
🦿 FBI: Hotel Wi-Fi is not safe 🦿

While hotel Wi-Fi is convenient, security is not the priority, federal government says.

πŸ“– Read

via "Tech Republic".
❌ LinkedIn, Instagram Vulnerable to Preview-Link RCE Security Woes ❌

Popular chat apps, including LINE, Slack, Twitter DMs and others, can also leak location data and share private info with third-party servers.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-6023 β€Ό

Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-10256 β€Ό

An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Employees Aware of Emailed Threats Open Suspicious Messages πŸ•΄

A survey of 1,000 employees finds 96% of employees are aware of digital threats, but 45% click emails they consider to be suspicious.

πŸ“– Read

via "Dark Reading".