🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
$100M Botnet Scheme Lands Cybercriminal 8 Years in Jail

Aleksandr Brovko faces jail time after stealing $100 million worth of personal identifiable information (PII) and financial data over the course of more than 10 years.

📖 Read

via "Threat Post".
🕴 Russian National Sentenced to 8 Years in Prison for Role in Botnet Operation 🕴

Cybercrime scheme netted more than $100 million.

📖 Read

via "Dark Reading".
🦿 Hackers have only just wet their whistle. Expect more ransomware and data breaches in 2021. 🦿

The COVID-19 pandemic provided a huge opening for bad actors this year, thanks to remote work. Security experts expect more advanced cybersecurity threats in the coming year.

📖 Read

via "Tech Republic".
🕴 New Tools Make North Korea's Kimsuky Group More Dangerous 🕴

Threat actor actively targeting US organizations in global intelligence-gathering campaign, government says.

📖 Read

via "Dark Reading".
CVE-2020-26939

In Legion of the Bouncy Castle BC before 1.55 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.

📖 Read

via "National Vulnerability Database".
CVE-2020-27982

IceWarp 11.4.5.0 allows XSS via the language parameter.

📖 Read

via "National Vulnerability Database".
CVE-2020-7758

This affects all versions of package browserless-chrome. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then sent back to a user. This can be escaped to fetch arbitrary files from a server.

📖 Read

via "National Vulnerability Database".
CVE-2020-9368

The Module Olea Gift On Order module through 5.0.8 for PrestaShop enables an unauthenticated user to read arbitrary files on the server via getfile.php?file=/.. directory traversal.

📖 Read

via "National Vulnerability Database".
CVE-2020-8183

A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.

📖 Read

via "National Vulnerability Database".
CVE-2020-6014

Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.

📖 Read

via "National Vulnerability Database".
🕴 Microsoft & Others Catalog Threats to Machine Learning Systems 🕴

Thirteen organizations worked together to create a dictionary of techniques used to attack ML models and warn that such malicious efforts will become more common.

📖 Read

via "Dark Reading".
🕴 California's Prop. 24 Splits Privacy Advocates 🕴

Critics worry that the curatives in Prop. 24 are worse than the disease of privacy-rights violations.

📖 Read

via "Dark Reading".
CVE-2020-9861

A stack overflow issue existed in Swift for Linux. The issue was addressed with improved input validation for dealing with deeply nested malicious JSON input.

📖 Read

via "National Vulnerability Database".
CVE-2020-16001

Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
CVE-2020-15973

Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension.

📖 Read

via "National Vulnerability Database".
CVE-2020-16007

Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.

📖 Read

via "National Vulnerability Database".
CVE-2020-15987

Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC stream.

📖 Read

via "National Vulnerability Database".
CVE-2020-16010

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
CVE-2020-6557

Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
🕴 6 Cybersecurity Lessons From 2020 🕴

The COVID-19 pandemic exposed new weaknesses in enterprise cybersecurity preparedness.

📖 Read

via "Dark Reading".
Oracle Rushes Emergency Fix for Critical WebLogic Server Flaw

The remote code-execution flaw (CVE-2020-14750) is low-complexity and requires no user interaction to exploit.

📖 Read

via "Threat Post".