πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-3638 β€Ό

u'An Unaligned address or size can propagate to the database due to improper page permissions and can lead to improper access control' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Agatti, Bitra, Kamorta, QCA6390, QCS404, QCS610, Rennell, SA515M, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-11174 β€Ό

u'Array index underflow issue in adsp driver due to improper check of channel id before used as array index.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in Agatti, APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ4019, IPQ5018, IPQ6018, IPQ8064, IPQ8074, Kamorta, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8953, MSM8996AU, QCA6390, QCA9531, QCM2150, QCS404, QCS405, QCS605, SA415M, SA515M, SA6155P, SA8155P, Saipan, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM8150, SM8250, SXR1130, SXR2130

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-3693 β€Ό

u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8098, Bitra, MSM8909W, MSM8996AU, Nicobar, QCM2150, QCS605, Saipan, SDM429W, SDX20, SM6150, SM8150, SM8250, SXR2130

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ As Businesses Go Remote, Hackers Find New Security Gaps πŸ•΄

Improper access control, information disclosure, and SSRF are among the most impactful, and most awarded, security flaws found this year.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How Can I Help Remote Workers Secure Their Home Routers? πŸ•΄

The most effective way is with employee security education.

πŸ“– Read

via "Dark Reading".
❌ Unpatched Windows Zero-Day Exploited in the Wild for Sandbox Escape ❌

Google Project Zero disclosed the bug before a patch becomes available from Microsoft.

πŸ“– Read

via "Threat Post".
πŸ•΄ Fraud Prevention Strategies to Prepare for the Future πŸ•΄

While companies have largely adjusted to the new normal for security management, here are some tips for combatting fraud, post-COVID.

πŸ“– Read

via "Dark Reading".
❌ Scammers Abuse Google Drive to Send Malicious Links ❌

Cybercriminals are sending malicious links to hundreds of thousands of users via Google Drive notifications.

πŸ“– Read

via "Threat Post".
❌ Texas Gold-Dealer Mined for Payment Details in Months-Long Data Breach ❌

JM Bullion fell victim to a payment-card skimmer, which was in place for five months.

πŸ“– Read

via "Threat Post".
πŸ›  SQLMAP - Automatic SQL Injection Tool 1.4.11 πŸ› 

sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Samhain File Integrity Checker 4.4.3 πŸ› 

Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.

πŸ“– Read

via "Packet Storm Security".
🦿 It's an urgent plea this Election Eve: Don't click on ransomware disguised as political ads 🦿

Remote work and social media have made it easier for businesses to be impacted by security breaches. Here's why, and how organizations can protect themselves.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2018-19951 β€Ό

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-19955 β€Ό

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.

πŸ“– Read

via "National Vulnerability Database".
❌ WordPress Pushes Out Multiple Flawed Security Updates ❌

WordPress bungles critical security 5.5.2 fix and saves face next day with 5.5.3 update.

πŸ“– Read

via "Threat Post".
πŸ” Digital Guardian Provides Customers Protection Following Spread of Ryuk Ransomware πŸ”

We’ve released a free policy pack to help customers, especially those in the healthcare and public health sector, protect against the latest Ryuk ransomware campaign.

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Windows Zero-Day Used with Chrome Flaw in Targeted Attacks πŸ•΄

Google's Project Zero has disclosed a Windows kernel zero-day vulnerability being used with a known Chrome bug in targeted attacks.

πŸ“– Read

via "Dark Reading".
❌ Survey: Cybersecurity Skills Shortage is β€˜Bad,’ But There’s Hope ❌

Automation, strategic process design and an investment in training are the keys to managing the cybersecurity skills gap, according to a recent survey from Trustwave.

πŸ“– Read

via "Threat Post".
❌ $100M Botnet Scheme Lands Cybercriminal 8 Years in Jail ❌

Aleksandr Brovko faces jail time after stealing $100 million worth of personal identifiable information (PII) and financial data over the course of more than 10 years.

πŸ“– Read

via "Threat Post".
πŸ•΄ Russian National Sentenced to 8 Years in Prison for Role in Botnet Operation πŸ•΄

Cybercrime scheme netted more than $100 million.

πŸ“– Read

via "Dark Reading".
🦿 Hackers have only just wet their whistle. Expect more ransomware and data breaches in 2021. 🦿

The COVID-19 pandemic provided a huge opening for bad actors this year, thanks to remote work. Security experts expect more advanced cybersecurity threats in the coming year.

πŸ“– Read

via "Tech Republic".