πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-27989 β€Ό

Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4692 β€Ό

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user to obtain sensitive information from the Dashboard UI. IBM X-Force ID: 186780.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28692 β€Ό

In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4566 β€Ό

IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially highly sensitive information in log files that could be read by an authenticated user. IBM X-Force ID: 184083.

πŸ“– Read

via "National Vulnerability Database".
🦿 Cybersecurity: Top hackers make big money from bug bounties 🦿

You might not make a million dollars, but hackers are making good money from reporting vulnerabilities.

πŸ“– Read

via "Tech Republic".
❌ Citrix SD-WAN Bugs Allow Remote Code Execution ❌

The bugs tracked as CVE-2020–8271, CVE-2020–8272 and CVE-2020–8273 exist in the Citrix SD-WAN Center.

πŸ“– Read

via "Threat Post".
🦿 Data is worth its weight in gold 🦿

IT leaders are placing an increased, permanent focus on the value of data, digital transformation, and security, a new survey finds.

πŸ“– Read

via "Tech Republic".
πŸ” Amendments to Singapore's Personal Data Protection Act Take Effect πŸ”

Singapore's recently amended Personal Data Protection Act (PDPA) increases the penalizations imposed on companies for data breaches and recognizes the rights of individuals to protect their personal data.

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Twitter Taps Mudge πŸ•΄

Noted security researcher Peiter Zatko joins the social network as head of security.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-5424 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26510 β€Ό

Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26508 β€Ό

The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26509 β€Ό

Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.

πŸ“– Read

via "National Vulnerability Database".
❌ Attackers Target Porn Site Goers in β€˜Malsmoke’ Zloader Attack ❌

A fake Java update found on various porn sites actually downloads the well-known Zloader malware.

πŸ“– Read

via "Threat Post".
❌ Dating Site Bumble Leaves Swipes Unsecured for 100M Users ❌

An API bug exposed personal information of users like political leanings, astrological signs, education, and even height and weight, and their distance away in miles.

πŸ“– Read

via "Threat Post".
πŸ•΄ Global Pandemic Fuels Cyber-Threat Workload for National Cyber Security Centre, Shows Annual Review πŸ•΄

From securing the Nightingale hospitals to tackling threats to vaccine research and production, a large part of the National Cyber Security Centre's (NCSC) recent work in the UK has been related to the coronavirus pandemic, as Ron Alalouff discovered when reporting on its Annual Review.

πŸ“– Read

via "Dark Reading".
⚠ Cult videogame company Capcom pays a big round $0.00 to ransomware crooks ⚠

Bad news: data stolen, data dumped, customers affected. Good news: crooks got $0. The ransom was $11M, so that's a big deal!

πŸ“– Read

via "Naked Security".
πŸ•΄ Breakdown of a Break-in: A Manufacturer's Ransomware Response πŸ•΄

The analysis of an industrial ransomware attack reveals common tactics and proactive steps that businesses can take to avoid similar incidents.

πŸ“– Read

via "Dark Reading".
🦿 4 ways to keep your company's and customers' data private and build trust 🦿

Implementing appropriate data privacy is critical for company operations and success. Learn some of the challenges and solutions recommended to do the job right.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-26224 β€Ό

In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function that allows a shopping cart to be recreated from an order already placed. The problem is fixed in 1.7.6.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27483 β€Ό

Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectIQ application to the ConnectIQ store. The ConnectIQ program interpreter trusts the offset provided for the stack value duplication instruction, DUP. The offset is unchecked and memory prior to the start of the execution stack can be read and treated as a TVM object. A successful exploit could use the vulnerability to leak runtime information such as the heap handle or pointer for a number of TVM context variables. Some reachable values may be controlled enough to forge a TVM object on the stack, leading to possible remote code execution.

πŸ“– Read

via "National Vulnerability Database".