πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Baidu Android apps caught leaking sensitive data from devices 🦿

Capturing the phone's IMSI number and MAC address, the leaked data could have made users trackable, potentially over their lifetimes, says Palo Alto Networks.

πŸ“– Read

via "Tech Republic".
⚠ Naked Security Live – Beat the Threat! ⚠

Here's the latest Naked Security Live video - how to beat the crooks! Watch now...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-4002 β€Ό

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An authenticated SD-WAN Orchestrator user with high privileges may be able to execute arbitrary code on the underlying operating system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4003 β€Ό

VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. An authenticated SD-WAN Orchestrator user may inject code into SQL queries which may lead to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29006 β€Ό

MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25472 β€Ό

SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-3985 β€Ό

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privilege escalation issue. An authenticated SD-WAN Orchestrator user may exploit an application weakness and call a vulnerable API to elevate their privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25473 β€Ό

SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25474 β€Ό

SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4000 β€Ό

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversal. An authenticated SD-WAN Orchestrator user is able to traversal directories which may lead to code execution of files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25475 β€Ό

SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-3984 β€Ό

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call using specially crafted SQL queries which may lead to unauthorized data access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4001 β€Ό

The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.

πŸ“– Read

via "National Vulnerability Database".
❌ Baidu Apps in Google Play Leak Sensitive Data ❌

Cyberattackers could use the information to track users across devices, disable phone service, or intercept messages and phone calls.

πŸ“– Read

via "Threat Post".
❌ Smart Doorbells on Amazon, eBay, Harbor Serious Security Issues ❌

Matt Lewis, with NCC Group, talks to Threatpost about a slew of security and privacy issues found in smart doorbells that are being sold on Amazon and eBay.

πŸ“– Read

via "Threat Post".
⚠ Gift card hack exposed – you pay, they play ⚠

These crooks hacked into a network hoping to get everyone in the company to buy them gift cards.

πŸ“– Read

via "Naked Security".
πŸ” FBI Warns of Spoofed FBI Websites πŸ”

The FBI is urging the American public to ensure they're getting "reliable and verified FBI information."

πŸ“– Read

via "Digital Guardian".
πŸ•΄ US Treasury's OFAC Ransomware Advisory: Navigating the Gray Areas πŸ•΄

Leveraging the right response strategy, following the regulations, and understanding the ransom entity are the fundamentals in any ransomware outbreak.

πŸ“– Read

via "Dark Reading".
πŸ•΄ What's in Store for Privacy in 2021 πŸ•΄

Changes are coming to the privacy landscape, including more regulations and technologies.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-13620 β€Ό

Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28994 β€Ό

A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.

πŸ“– Read

via "National Vulnerability Database".