🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2019-8746

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

📖 Read

via "National Vulnerability Database".
CVE-2020-9932

A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, tvOS 13. Processing maliciously crafted web content may lead to arbitrary code execution.

📖 Read

via "National Vulnerability Database".
CVE-2018-4433

A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, watchOS 5, iOS 12, tvOS 12, macOS Mojave 10.14. A malicious application may be able to modify protected parts of the file system.

📖 Read

via "National Vulnerability Database".
CVE-2018-4339

This issue was addressed with a new entitlement. This issue is fixed in iOS 12.1. A local user may be able to read a persistent device identifier.

📖 Read

via "National Vulnerability Database".
CVE-2019-8858

A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. A user who shares their screen may not be able to end screen sharing.

📖 Read

via "National Vulnerability Database".
CVE-2020-9941

This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to unexpectedly alter application state.

📖 Read

via "National Vulnerability Database".
CVE-2020-9782

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A remote attacker may be able to overwrite existing files.

📖 Read

via "National Vulnerability Database".
CVE-2020-25765

Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140.

📖 Read

via "National Vulnerability Database".
CVE-2019-8715

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15, iOS 13. An application may be able to execute arbitrary code with system privileges.

📖 Read

via "National Vulnerability Database".
🕴 Survey Uncovers High Level of Concern Over Firewalls 🕴

More than half of respondents are planning to reduce their network firewall footprint because of what they see as limitations in the technology.

📖 Read

via "Dark Reading".
CVE-2020-16140

The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.

📖 Read

via "National Vulnerability Database".
CVE-2020-27957

The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.

📖 Read

via "National Vulnerability Database".
CVE-2020-27956

An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).

📖 Read

via "National Vulnerability Database".
🦿 Security firm identifies 5 biggest cybersecurity risks for hospitals and healthcare organizations 🦿

Wandera finds malicious network traffic and configuration vulnerabilities on mobile devices as popular entry points for cybercriminals.

📖 Read

via "Tech Republic".
Trump Campaign Website Defaced by Cryptocurrency Scam

Hackers claim to have access to classified information linking the president to the origin of the coronavirus and criminal collusion with foreign actors.

📖 Read

via "Threat Post".
Experts Weigh in on E-Commerce Security Amid Snowballing Threats

How a retail sector reeling from COVID-19 can lock down their online systems to prevent fraud during the upcoming holiday shopping spike.

📖 Read

via "Threat Post".
CVE-2020-5145

SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execution in the target system.

📖 Read

via "National Vulnerability Database".
North Korea-Backed Spy Group Poses as Reporters in Spearphishing Attacks, Feds Warn

The Kimsuky/Hidden Cobra APT is going after the commercial sector, according to CISA.

📖 Read

via "Threat Post".
Election Security: How Mobile Devices Are Shaping the Way We Work, Play and Vote

With the election just a week away, cybercriminals are ramping up mobile attacks on citizens under the guise of campaign communications.

📖 Read

via "Threat Post".
🕴 Physical Security Has a Lot of Catching Up to Do 🕴

The transformation we need: merging the network operations center with the physical security operations center.

📖 Read

via "Dark Reading".
CVE-2020-8240

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.

📖 Read

via "National Vulnerability Database".