πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-27387 β€Ό

An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on the server) with the PHP extension, and finally executing the PHP file via an HTTP GET request to /storage/<php_file_name>. NOTE: the vendor has patched this while leaving the version number at 1.0.0-beta.

πŸ“– Read

via "National Vulnerability Database".
❌ Malspam Campaign Milks Election Uncertainty ❌

Emails try to lure victims with malicious documents claiming to have information about voting interference.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-7761 β€Ό

This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted invalid emails.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep5: Chrome, Flash and malware for sale [Podcast] ⚠

Here's the latest podcast - listen now!

πŸ“– Read

via "Naked Security".
πŸ•΄ The One Critical Element to Hardening Your Employees' Mobile Security πŸ•΄

COVID-19 has exposed longstanding gaps in enterprise mobile security. Creating a comprehensive mobile security plan and mandating compliance with that plan are essential to closing them.

πŸ“– Read

via "Dark Reading".
❌ Cisco Zero-Day in AnyConnect Secure Mobility Client Remains Unpatched ❌

Cisco also disclosed high-severity vulnerabilities in its Webex and SD-WAN products.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-7763 β€Ό

This affects the package phantom-html-to-pdf before 0.6.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Online Users Feel Safe, But Risky Behavior Abounds πŸ•΄

New research also shows a divide between younger and older users in their security practices, including use of two-factor authentication and how often software updates are performed.

πŸ“– Read

via "Dark Reading".
🦿 Don't click on ransomware disguised as political ads 🦿

Remote work and social media have made it easier for businesses to be impacted by security breaches. Here's why, and how organizations can protect themselves.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-27402 β€Ό

The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su binary via a serial port (UART) connection or using adb.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-15949 β€Ό

Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cado Security Gets $1.5 Million Seed πŸ•΄

The seed funding round was led by Ten Eleven Ventures.

πŸ“– Read

via "Dark Reading".
🦿 How to defend your organization against social engineering attacks 🦿

A security awareness program backed by multi-factor authentication can help protect your critical assets, says NordVPN Teams.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Digital Transformation Means Security Must Also Transform πŸ•΄

Being successful in this moment requires the ability to evolve in terms of team management, visibility, and crisis management.

πŸ“– Read

via "Dark Reading".
🦿 How to enable end-to-end encryption for the Nextcloud app 🦿

Learn how you can enable the new Nextcloud end-to-end encryption.

πŸ“– Read

via "Tech Republic".
🦿 How to manage your personal information for your Google account 🦿

In the name of security, you should make sure the information displayed on your Google account is limited. Jack Wallen shows you how.

πŸ“– Read

via "Tech Republic".
🦿 How to manage personal information for your Google account 🦿

In the name of security, make sure the information displayed on your Google account is limited. Jack Wallen shows you how.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2018-1725 β€Ό

IBM QRadar SIEM 7.3 and 7.4 n a multi tenant configuration could be vulnerable to information disclosure. IBM X-Force ID: 147440.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26507 β€Ό

A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the Ò€&oelig;NotesҀ� functionality in the main screen, an attacker can inject a payload into the Ò€&oelig;DescriptionҀ� field under the Ò€&oelig;Insert To-DoҀ� option. Other users might download this data, for example a CSV file, and execute the malicious commands on their computer by opening the file using a software such as Microsoft Excel. The attacker could gain remote access to the userÒ€ℒs PC.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4097 β€Ό

In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14240 β€Ό

HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

πŸ“– Read

via "National Vulnerability Database".