πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Experian predicts 5 key data breach targets for 2021 🦿

The pandemic warfare will shift to vaccine supply chains, home networks, and data from telemedicine visits in the new year.

πŸ“– Read

via "Tech Republic".
πŸ•΄ NortonLifeLock Acquires Avira for $360M πŸ•΄

The all-cash transaction is expected to broaden NortonLifeLock's international presence and bring a freemium business model into its portfolio.

πŸ“– Read

via "Dark Reading".
❌ β€˜Free’ Cyberpunk 2077 Downloads Lead to Data Harvesting ❌

The hotly anticipated game -- featuring a digital Keanu Reeves as a major character -- is being used as a lure for cyberattacks.

πŸ“– Read

via "Threat Post".
❌ Europol Warns COVID-19 Vaccine Rollout Vulnerable to Fraud, Theft ❌

With the promise of a widely available COVID-19 vaccine on the horizon, Europol, the European Union’s law-enforcement agency, has issued a warning about the rise of vaccine-related Dark Web activity. The agency joins a chorus of security professionals that have concerns about widespread attacks on the COVID-19 vaccine rollout. The warning comes after Europol discovered […]

πŸ“– Read

via "Threat Post".
🦿 How cybercrime will cost the world $1 trillion this year 🦿

Including both financial losses and cybersecurity spending, the $1 trillion in costs will represent a 50% increase over 2018, says McAfee.

πŸ“– Read

via "Tech Republic".
🦿 Malwarebytes: Schools still struggling with connectivity and using last year's antivirus software 🦿

About half of IT decision makers in a new survey say they have not added any cybersecurity training for teachers and students since remote learning started.

πŸ“– Read

via "Tech Republic".
πŸ•΄ NSA Warns of Exploits Targeting Recently Disclosed VMware Vulnerability πŸ•΄

Agency urges organizations to deploy patch as soon as possible since exploit activity is hard to detect.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Magic Behind the Magic πŸ•΄

And oldie but goodie and still pretty truey.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-29595 β€Ό

PlugIns\IDE_ACDStd.apl in ACDSee Photo Studio Studio Professional 2021 14.0 Build 1705 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x00000000000031aa.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-17521 β€Ό

Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29597 β€Ό

IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29600 β€Ό

In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29599 β€Ό

ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13945 β€Ό

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

πŸ“– Read

via "National Vulnerability Database".
🦿 How to use an SSH config file on macOS for easier connections to your data center servers 🦿

Jack Wallen shows you how to make SSH connections even easier from your macOS machine.

πŸ“– Read

via "Tech Republic".
❌ Rana Android Malware Updates Allow WhatsApp, Telegram IM Snooping ❌

The developers behind the Android malware have a new variant that spies on instant messages in WhatsApp, Telegram, Skype and more.

πŸ“– Read

via "Threat Post".
🦿 Multi-factor authentication: 5 reasons not to use SMS 🦿

Using SMS as an additional means to authenticate your password is better than nothing, but it's not the most reliable. Tom Merritt lists five reasons why SMS should not be used for MFA.

πŸ“– Read

via "Tech Republic".
🦿 Top 5 reasons not to use SMS for multi-factor authentication 🦿

Using SMS as an additional means to authenticate your password is better than nothing, but it's not the most reliable. Tom Merritt lists five reasons why SMS should not be used for MFA.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Trump Signs IoT Security Bill into Law πŸ•΄

The Internet of Things Cybersecurity Improvement Act of 2020 is now official.

πŸ“– Read

via "Dark Reading".
❌ NSA Warns: Patched VMware Bug Under Active Exploit ❌

Feds are warning that foreign adversaries are exploiting a weeks-old bug in VMware’s Workspace One Access and VMware Identity Manager products.

πŸ“– Read

via "Threat Post".
πŸ•΄ Phishing Campaign Targets 200M Microsoft 365 Accounts πŸ•΄

A well-organized email spoofing campaign has been seen targeting financial services, insurance, healthcare, manufacturing, utilities, and telecom.

πŸ“– Read

via "Dark Reading".