πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-27182 β€Ό

Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, ixedit/editor_component.jsp, or the login form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27183 β€Ό

A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges of arbitrary user accounts, and have unspecified other impact.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-8956 β€Ό

Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.

πŸ“– Read

via "National Vulnerability Database".
❌ Google Boots 21 Bogus Gaming Apps from Play Marketplace ❌

Android apps packed with malware from HiddenAds family downloaded 8 million times from the online marketplace.

πŸ“– Read

via "Threat Post".
❌ Holiday Shopping Craze, COVID-19 Spur Retail Security Storm ❌

Veracode's Chris Eng discusses the cyber threats facing shoppers who are going online due to the pandemic and the imminent holiday season.

πŸ“– Read

via "Threat Post".
πŸ•΄ COVID-19: Latest Security News & Commentary πŸ•΄

Check out Dark Reading's updated, exclusive news and commentary surrounding the coronavirus pandemic.

πŸ“– Read

via "Dark Reading".
❌ Majority of Microsoft 365 Admins Don’t Enable MFA ❌

Beyond admins, researchers say that 97 percent of all total Microsoft 365 users do not use multi-factor authentication.

πŸ“– Read

via "Threat Post".
🦿 How foreign actors are trying to undermine the US presidential election 🦿

Through disinformation campaigns, foreign adversaries attempt to exploit the fear and uncertainty among US voters, says Digital Shadows.

πŸ“– Read

via "Tech Republic".
🦿 FBI: Hotel Wi-Fi is not safe 🦿

While hotel Wi-Fi is convenient, security is not the priority, federal government says.

πŸ“– Read

via "Tech Republic".
❌ LinkedIn, Instagram Vulnerable to Preview-Link RCE Security Woes ❌

Popular chat apps, including LINE, Slack, Twitter DMs and others, can also leak location data and share private info with third-party servers.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-6023 β€Ό

Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-10256 β€Ό

An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Employees Aware of Emailed Threats Open Suspicious Messages πŸ•΄

A survey of 1,000 employees finds 96% of employees are aware of digital threats, but 45% click emails they consider to be suspicious.

πŸ“– Read

via "Dark Reading".
🦿 Going passwordless might be safer for organizations 🦿

Passwords are a constant struggle for businesses and IT departments. There are other ways to stay safe.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Akamai Acquires Asavie πŸ•΄

Asavie's mobile, IoT, and security products and services will become part of the Akamai Security and Personalization Services product line.

πŸ“– Read

via "Dark Reading".
🦿 Top 5 things to know about EU-US data privacy 🦿

For companies with data users in both the EU and the US, laws protecting users' privacy vary. Tom Merritt lists five things to know about EU-US data privacy.

πŸ“– Read

via "Tech Republic".
🦿 Top 5 things to know about EU-US data privacy 🦿

For companies with data users in both the EU and the US, laws protecting users' privacy vary. Tom Merritt lists five things to know about EU-US data privacy.

πŸ“– Read

via "Tech Republic".
πŸ•΄ MITRE Shield Matrix Highlights Deception & Concealment Technology πŸ•΄

The role that these technologies play in the MITRE Shield matrix is a clear indicator that they are an essential part of today's security landscape.

πŸ“– Read

via "Dark Reading".
⚠ Facebook β€œcopyright violation” tries to get past 2FA – don’t fall for it! ⚠

Watch out for "Facebook copyright violation" emails - even if they link straight back to Facebook.com

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-11854 β€Ό

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-11858 β€Ό

Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Bridge (containerized). The vulneravility affects: 1.) Operation Bridge Manager versions: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) versions: 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. The vulnerability could allow local attackers to execute code with escalated privileges.

πŸ“– Read

via "National Vulnerability Database".