πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-5638 β€Ό

Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5678 β€Ό

Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5680 β€Ό

Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vector.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5679 β€Ό

Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.

πŸ“– Read

via "National Vulnerability Database".
❌ Code42 Incydr Series: Honing in on High-Risk Users with Code42 Incydr ❌

Incydr lets you monitor your high-risk users without impeding their ongoing work.

πŸ“– Read

via "Threat Post".
❌ Clop Gang Makes Off with 2M Credit Cards from E-Land ❌

The ransomware group pilfered payment-card data and credentials for over a year, before ending with an attack last month that shut down many of the South Korean retailer’s stores.

πŸ“– Read

via "Threat Post".
πŸ•΄ From FUD to Fix: Why the CISO-Vendor Partnership Needs to Change Now πŸ•΄

CISOs and their staffs are up against too many systems, screens, and alerts, with too few solutions to effectively address pain points.

πŸ“– Read

via "Dark Reading".
❌ As Modern Mobile Enables Remote Work, It Also Demands Security ❌

Smartphones, tablets, collaboration apps and other modern framework tools are critical to maintaining productivity remotely, but they also demand an integrated security strategy purpose-built for mobile devices. The coronavirus pandemic has completely upended the way we work, educate and socialize. Soon after the rapid onset of the virus, organizations were forced to fully adopt work-from-home […]

πŸ“– Read

via "Threat Post".
⚠ S3 Ep9: Gift card hacks, dubious doorbells and Wi-Fi tips [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-6017 β€Ό

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text messages, leading to a Heap-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-6021 β€Ό

Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint clientÒ€ℒs privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-6111 β€Ό

An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 16.000, Series B FRN 15.002, Series B FRN 15.000, Series B FRN 14.000, Series B FRN 13.000, Series B FRN 12.000, Series B FRN 11.000 and Series B FRN 10.000. A specially crafted packet can cause a major error, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
❌ Cyberattacks Target COVID-19 Vaccine β€˜Cold-Chain’ Orgs ❌

Cybercriminals try to steal the credentials of top companies associated with the COVID-19 vaccine supply chain in an espionage effort.

πŸ“– Read

via "Threat Post".
🦿 Popular Android apps still vulnerable to patched security flaw 🦿

Cybercriminals can exploit the at-risk apps to steal login credentials, passwords, financial details, and text messages, says Check Point.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-2320 β€Ό

Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28937 β€Ό

OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2324 β€Ό

Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2322 β€Ό

Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28939 β€Ό

OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14318 β€Ό

A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2321 β€Ό

A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a project.

πŸ“– Read

via "National Vulnerability Database".