πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-27986 β€Ό

** DISPUTED ** SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position is "it is the administrator's responsibility to configure it."

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-11487 β€Ό

NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC firmware in which the use of a hard-coded RSA 1024 key with weak ciphers may lead to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-11488 β€Ό

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware signature, which may lead to information disclosure or code execution.

πŸ“– Read

via "National Vulnerability Database".
❌ Xfinity, McAfee Brands Abused by Parked Domains in Active Campaigns ❌

Malicious redirection websites are using typosquatting and impersonation to attack unwary visitors.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-27655 β€Ό

Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7746 β€Ό

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.

πŸ“– Read

via "National Vulnerability Database".
❌ Bug-Bounty Awards Spike 26% in 2020 ❌

The most-rewarded flaw is XSS, which is among those that are relatively cheap for organizations to identify.

πŸ“– Read

via "Threat Post".
🦿 How phishing attacks are targeting schools and colleges 🦿

Attackers are exploiting the need for schools to receive critical updates from teachers, principals, and department heads, says Barracuda.

πŸ“– Read

via "Tech Republic".
πŸ” Digital Guardian Debuts Exclusive Offer for Forcepoint DLP Customers πŸ”

With news the company will be acquired, Forcepoint DLP customers may be looking for a change.

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Is Your Encryption Ready for Quantum Threats? πŸ•΄

Answers to these five questions will help security teams defend against attackers in the post-quantum computing era.

πŸ“– Read

via "Dark Reading".
❌ Oracle WebLogic Server RCE Flaw Under Active Attack ❌

The flaw in the console component of the WebLogic Server, CVE-2020-14882, is under active attack, researchers warn.

πŸ“– Read

via "Threat Post".
🦿 FBI: Hospitals and healthcare providers face imminent ransomware threat 🦿

The FBI warns of a threat against the healthcare sector from Ryuk ransomware, and one that's already affected some hospitals.

πŸ“– Read

via "Tech Republic".
❌ Home Depot Confirms Data Breach in Order Confirmation SNAFU ❌

Hundreds of emailed order confirmations for random strangers were sent to Canadian customers, each containing personal information.

πŸ“– Read

via "Threat Post".
πŸ•΄ How to Increase Voter Turnout & Reduce Fraud πŸ•΄

Digital identity verification has advanced, both technologically and legislatively. Is it the answer to simpler, safer voting?

πŸ“– Read

via "Dark Reading".
⚠ Buer Loader β€œmalware-as-a-service” joins Emotet for ransomware delivery ⚠

A relative newcomer in the "malware-as-a-service" scene is starting to attract the big-money ransomware criminals.

πŸ“– Read

via "Naked Security".
πŸ•΄ Cybercriminals Aim BEC Attacks at Education Industry πŸ•΄

Heightened vulnerability comes at a time when the sector has been focusing on setting up a remote workforce and online learning amid the pandemic.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Why Defense, Not Offense, Will Determine Global Cyber Powers πŸ•΄

Darktrace director of strategic threat Marcus Fowlers explains what to expect from nation-state attackers in the months to come -- and why kindergarten classes are a good model for solid cybersecurity.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How Healthcare Organizations Can Combat Ransomware πŸ•΄

The days of healthcare organizations relying solely on endpoint security software to stop attacks are over. Here are six ways that healthcare providers can fight the ever-present threat.

πŸ“– Read

via "Dark Reading".
🦿 Business Email Compromise attacks are on the rise 🦿

BEC campaigns continue to shift their targets from C-suite executives and finance employees to group mailboxes, says Abnormal Security.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Ransomware Wave Targets US Hospitals: What We Know So Far πŸ•΄

A joint advisory from the CSIA, FBI, and HHS warns of an "increased and imminent" threat to US hospitals and healthcare providers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Hackers Make Off With Millions From Wisconsin Republicans πŸ•΄

According to the Wisconsin Republican Party, thieves used altered invoices to make off with $2.3 million in election funds.

πŸ“– Read

via "Dark Reading".