🕴 US Government Issues Warning on Kimsuky APT Group 🕴
📖 Read
via "Dark Reading".
The joint alert, from CISA, the FBI, and others, describes activities from the North Korean advanced persistent threat group.📖 Read
via "Dark Reading".
Dark Reading
US Government Issues Warning on Kimsuky APT Group
The joint alert, from CISA, the FBI, and others, describes activities from the North Korean advanced persistent threat group.
🦿 Don't wait for a breach before implementing cybersecurity, expert says 🦿
📖 Read
via "Tech Republic".
Professor who specializes in security says we often treat a breach like a home break-in, adding security after the theft. More students are choosing security as a career, she adds.📖 Read
via "Tech Republic".
TechRepublic
Don't wait for a breach before implementing cybersecurity, expert says
Professor who specializes in security says we often treat a breach like a home break-in, adding security after the theft. More students are choosing security as a career, she adds.
❌ More Hospitals Hit by Growing Wave of Ransomware Attacks ❌
📖 Read
via "Threat Post".
Hospitals in New York and Oregon were targeted on Tuesday by threat actors who crippled systems and forced ambulances with sick patients to be rerouted, in some cases.📖 Read
via "Threat Post".
Threat Post
2 More Hospitals Hit by Growing Wave of Ransomware Attacks, As Feds Issue Warning
Hospitals in New York and Oregon were targeted on Tuesday by threat actors who crippled systems and forced ambulances with sick patients to be rerouted, in some cases.
🕴 Breaking the Glass Ceiling: Tough for Women, Tougher for Women of Color 🕴
📖 Read
via "Dark Reading".
Security practitioners shed light on obstacles limiting career growth and the steps businesses can take to achieve their promises of a more diverse workforce.📖 Read
via "Dark Reading".
Dark Reading
Breaking the Glass Ceiling: Tough for Women, Tougher for Women of Color
Security practitioners shed light on obstacles limiting career growth and the steps businesses can take to achieve their promises of a more diverse workforce.
‼ CVE-2020-24712 ‼
📖 Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-24711 ‼
📖 Read
via "National Vulnerability Database".
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack📖 Read
via "National Vulnerability Database".
‼ CVE-2020-24708 ‼
📖 Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27986 ‼
📖 Read
via "National Vulnerability Database".
** DISPUTED ** SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position is "it is the administrator's responsibility to configure it."📖 Read
via "National Vulnerability Database".
‼ CVE-2020-11487 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC firmware in which the use of a hard-coded RSA 1024 key with weak ciphers may lead to information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-11488 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware signature, which may lead to information disclosure or code execution.📖 Read
via "National Vulnerability Database".
❌ Xfinity, McAfee Brands Abused by Parked Domains in Active Campaigns ❌
📖 Read
via "Threat Post".
Malicious redirection websites are using typosquatting and impersonation to attack unwary visitors.📖 Read
via "Threat Post".
Threat Post
Xfinity, McAfee Brands Abused by Parked Domains in Active Campaigns
Malicious redirection websites are using typosquatting and impersonation to attack unwary visitors.
‼ CVE-2020-27655 ‼
📖 Read
via "National Vulnerability Database".
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-7746 ‼
📖 Read
via "National Vulnerability Database".
This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.📖 Read
via "National Vulnerability Database".
❌ Bug-Bounty Awards Spike 26% in 2020 ❌
📖 Read
via "Threat Post".
The most-rewarded flaw is XSS, which is among those that are relatively cheap for organizations to identify.📖 Read
via "Threat Post".
Threat Post
Bug-Bounty Awards Spike 26% in 2020
The most-rewarded flaw is XSS, which is among those that are relatively cheap for organizations to identify.
🦿 How phishing attacks are targeting schools and colleges 🦿
📖 Read
via "Tech Republic".
Attackers are exploiting the need for schools to receive critical updates from teachers, principals, and department heads, says Barracuda.📖 Read
via "Tech Republic".
TechRepublic
How phishing attacks are targeting schools and colleges
Attackers are exploiting the need for schools to receive critical updates from teachers, principals, and department heads, says Barracuda.
🔏 Digital Guardian Debuts Exclusive Offer for Forcepoint DLP Customers 🔏
📖 Read
via "Digital Guardian".
With news the company will be acquired, Forcepoint DLP customers may be looking for a change.📖 Read
via "Digital Guardian".
Digital Guardian
Digital Guardian Debuts Exclusive Offer for Forcepoint DLP Customers
With news the company will be acquired, Forcepoint DLP customers may be looking for a change.
🕴 Is Your Encryption Ready for Quantum Threats? 🕴
📖 Read
via "Dark Reading".
Answers to these five questions will help security teams defend against attackers in the post-quantum computing era.📖 Read
via "Dark Reading".
Dark Reading
Is Your Encryption Ready for Quantum Threats?
Answers to these five questions will help security teams defend against attackers in the post-quantum computing era.
❌ Oracle WebLogic Server RCE Flaw Under Active Attack ❌
📖 Read
via "Threat Post".
The flaw in the console component of the WebLogic Server, CVE-2020-14882, is under active attack, researchers warn.📖 Read
via "Threat Post".
Threat Post
Oracle WebLogic Server RCE Flaw Under Active Attack
The flaw in the console component of the WebLogic Server, CVE-2020-14882, is under active attack, researchers warn.
🦿 FBI: Hospitals and healthcare providers face imminent ransomware threat 🦿
📖 Read
via "Tech Republic".
The FBI warns of a threat against the healthcare sector from Ryuk ransomware, and one that's already affected some hospitals.📖 Read
via "Tech Republic".
TechRepublic
FBI: Hospitals and healthcare providers face imminent ransomware threat
The FBI warns of a threat against the healthcare sector from Ryuk ransomware, and one that's already affected some hospitals.
❌ Home Depot Confirms Data Breach in Order Confirmation SNAFU ❌
📖 Read
via "Threat Post".
Hundreds of emailed order confirmations for random strangers were sent to Canadian customers, each containing personal information.📖 Read
via "Threat Post".
Threat Post
Home Depot Confirms Data Breach in Order Confirmation SNAFU
Hundreds of emailed order confirmations for random strangers were sent to Canadian customers, each containing personal information.
🕴 How to Increase Voter Turnout & Reduce Fraud 🕴
📖 Read
via "Dark Reading".
Digital identity verification has advanced, both technologically and legislatively. Is it the answer to simpler, safer voting?📖 Read
via "Dark Reading".
Dark Reading
How to Increase Voter Turnout & Reduce Fraud
Digital identity verification has advanced, both technologically and legislatively. Is it the answer to simpler, safer voting?