πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Hexagon Announces Deal to Acquire PAS Global πŸ•΄

The Houston-based PAS Global will operate as part of Hexagon's PPM (formerly Intergraph Process, Power & Marine) division.

πŸ“– Read

via "Dark Reading".
🦿 What's happening today: The election and online spending 🦿

As Americans anxiously await clarity regarding final voting counts and results of yesterday's election, a new report found 26% of US consumers correlate who will win with how much they'll spend.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-7128 β€Ό

A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28049 β€Ό

An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.

πŸ“– Read

via "National Vulnerability Database".
❌ Google Forms Abused to Phish AT&T Credentials ❌

More than 200 Google Forms impersonate top brands - including Microsoft OneDrive, Office 365, and Wells Fargo - to steal victims' credentials.

πŸ“– Read

via "Threat Post".
❌ GrowDiaries Exposes Emails, Passwords of 1.4M Cannabis Growers ❌

Cannabis journaling platform GrowDiaries exposed more than 3.4 million user records online, many from countries where pot is illegal.

πŸ“– Read

via "Threat Post".
❌ Mysterious APT Leaves Curious β€˜KilllSomeOne’ Clue ❌

APT cloaks identity using script-kiddie messages and advanced deployment and targeting techniques.

πŸ“– Read

via "Threat Post".
πŸ•΄ Disinformation Now the Top Concern Following Hack-Free Election Day πŸ•΄

After an Election Day without foreign interference and cyberattacks, security experts turn their focus to disinformation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-27691 β€Ό

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System Log Settings.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27692 β€Ό

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. Attackers can, for example, use this to update the TR-069 configuration server settings (responsible for managing devices remotely). This makes it possible to remotely reboot the device or upload malicious firmware.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26207 β€Ό

DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27690 β€Ό

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web management portal. When a POST request is sent to /boaform/admin/formDOMAINBLK with a large blkDomain value, the Boa server crashes.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Ransom Payment No Guarantee Against Doxxing πŸ•΄

Several organizations that paid a ransom to keep attackers from releasing stolen data saw it leaked anyway, according to Coveware.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-25201 β€Ό

HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27387 β€Ό

An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on the server) with the PHP extension, and finally executing the PHP file via an HTTP GET request to /storage/<php_file_name>. NOTE: the vendor has patched this while leaving the version number at 1.0.0-beta.

πŸ“– Read

via "National Vulnerability Database".
❌ Malspam Campaign Milks Election Uncertainty ❌

Emails try to lure victims with malicious documents claiming to have information about voting interference.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-7761 β€Ό

This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted invalid emails.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep5: Chrome, Flash and malware for sale [Podcast] ⚠

Here's the latest podcast - listen now!

πŸ“– Read

via "Naked Security".
πŸ•΄ The One Critical Element to Hardening Your Employees' Mobile Security πŸ•΄

COVID-19 has exposed longstanding gaps in enterprise mobile security. Creating a comprehensive mobile security plan and mandating compliance with that plan are essential to closing them.

πŸ“– Read

via "Dark Reading".
❌ Cisco Zero-Day in AnyConnect Secure Mobility Client Remains Unpatched ❌

Cisco also disclosed high-severity vulnerabilities in its Webex and SD-WAN products.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-7763 β€Ό

This affects the package phantom-html-to-pdf before 0.6.1.

πŸ“– Read

via "National Vulnerability Database".