πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Insider Threats Poised to Increase in 2021 πŸ”

Forrester, citing the persistence of remote work, predicts that internal incidents will be responsible for 33% of breaches in 2021.

πŸ“– Read

via "Digital Guardian".
πŸ•΄ 6 Ways Passwords Fail Basic Security Tests πŸ•΄

New data shows humans still struggle with password creation and management.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-16262 β€Ό

Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26132 β€Ό

An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the HomeDNSServer.exe binary.

πŸ“– Read

via "National Vulnerability Database".
❌ β€˜Copyright Violation’ Notices Lead to Facebook 2FA Bypass ❌

Fraudulent Facebook messages allege copyright infringement and threaten to take down pages, unless users enter logins, passwords and 2FA codes.

πŸ“– Read

via "Threat Post".
πŸ•΄ US Government Issues Warning on Kimsuky APT Group πŸ•΄

The joint alert, from CISA, the FBI, and others, describes activities from the North Korean advanced persistent threat group.

πŸ“– Read

via "Dark Reading".
🦿 Don't wait for a breach before implementing cybersecurity, expert says 🦿

Professor who specializes in security says we often treat a breach like a home break-in, adding security after the theft. More students are choosing security as a career, she adds.

πŸ“– Read

via "Tech Republic".
❌ More Hospitals Hit by Growing Wave of Ransomware Attacks ❌

Hospitals in New York and Oregon were targeted on Tuesday by threat actors who crippled systems and forced ambulances with sick patients to be rerouted, in some cases.

πŸ“– Read

via "Threat Post".
πŸ•΄ Breaking the Glass Ceiling: Tough for Women, Tougher for Women of Color πŸ•΄

Security practitioners shed light on obstacles limiting career growth and the steps businesses can take to achieve their promises of a more diverse workforce.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-24712 β€Ό

Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24711 β€Ό

The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24708 β€Ό

Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27986 β€Ό

** DISPUTED ** SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position is "it is the administrator's responsibility to configure it."

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-11487 β€Ό

NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC firmware in which the use of a hard-coded RSA 1024 key with weak ciphers may lead to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-11488 β€Ό

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware signature, which may lead to information disclosure or code execution.

πŸ“– Read

via "National Vulnerability Database".
❌ Xfinity, McAfee Brands Abused by Parked Domains in Active Campaigns ❌

Malicious redirection websites are using typosquatting and impersonation to attack unwary visitors.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-27655 β€Ό

Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7746 β€Ό

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.

πŸ“– Read

via "National Vulnerability Database".
❌ Bug-Bounty Awards Spike 26% in 2020 ❌

The most-rewarded flaw is XSS, which is among those that are relatively cheap for organizations to identify.

πŸ“– Read

via "Threat Post".
🦿 How phishing attacks are targeting schools and colleges 🦿

Attackers are exploiting the need for schools to receive critical updates from teachers, principals, and department heads, says Barracuda.

πŸ“– Read

via "Tech Republic".
πŸ” Digital Guardian Debuts Exclusive Offer for Forcepoint DLP Customers πŸ”

With news the company will be acquired, Forcepoint DLP customers may be looking for a change.

πŸ“– Read

via "Digital Guardian".