‼ CVE-2020-26254 ‼
📖 Read
via "National Vulnerability Database".
omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during authentication. This vulnerability impacts applications using the omniauth-apple strategy of OmniAuth and using the info.email field of OmniAuth's Auth Hash Schema for any kind of identification. The value of this field may be set to any value of the attacker's choice including email addresses of other users. Applications not using info.email for identification but are instead using the uid field are not impacted in the same manner. Note, these applications may still be negatively affected if the value of info.email is being used for other purposes. Applications using affected versions of omniauth-apple are advised to upgrade to omniauth-apple version 1.0.1 or later.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29578 ‼
📖 Read
via "National Vulnerability Database".
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29577 ‼
📖 Read
via "National Vulnerability Database".
The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.📖 Read
via "National Vulnerability Database".
❌ Critical, Unpatched Bug Opens GE Radiological Devices to Remote Code Execution ❌
📖 Read
via "Threat Post".
A CISA alert is flagging a critical default credentials issue that affects 100+ types of devices found in hospitals, from MRI machines to surgical imaging.📖 Read
via "Threat Post".
Threat Post
Critical, Unpatched Bugs Open GE Radiological Devices to Remote Code Execution
A CISA alert is flagging a critical default credentials issue that affects 100+ types of devices found in hospitals, from MRI machines to surgical imaging.
🦿 How to protect yourself from gift card scams 🦿
📖 Read
via "Tech Republic".
With the holiday season in bloom, watch out for scams that promise free gift cards or offer to check your gift card balance, says Bolster.📖 Read
via "Tech Republic".
TechRepublic
How to protect yourself from gift card scams
With the holiday season in bloom, watch out for scams that promise free gift cards or offer to check your gift card balance, says Bolster.
🦿 Linux Foundation debuts new, secure, open source cloud native access management software platform 🦿
📖 Read
via "Tech Republic".
Based on the Gluu server, the Janssen Project prioritizes security and performance and features signing and encryption functionalities.📖 Read
via "Tech Republic".
TechRepublic
Linux Foundation debuts new, secure, open source cloud native access management software platform
Based on the Gluu server, the Janssen Project prioritizes security and performance and features signing and encryption functionalities.
🕴 Keeping Cyber Secure at Christmas 🕴
📖 Read
via "Dark Reading".
Sylvain Cortes, Security Evangelist and cybersecurity expert at Alsid, highlights the need for security departments to raise awareness through their organizations over cyber threats this Christmas.📖 Read
via "Dark Reading".
Dark Reading
Keeping Cyber Secure at Christmas
Sylvain Cortes, Security Evangelist and cybersecurity expert at Alsid, highlights the need for security departments to raise awareness through their organizations over cyber threats this Christmas.
🕴 Fortinet Purchases Panopta 🕴
📖 Read
via "Dark Reading".
The acquisition is intended to improve the visibility and automated response capabilities of Fortinet's Security Fabri.📖 Read
via "Dark Reading".
Dark Reading
Fortinet Purchases Panopta
The acquisition is intended to improve the visibility and automated response capabilities of Fortinet's Security Fabri.
🕴 Gula Tech Foundation to Award $1M in Grants to Infosec Nonprofits 🕴
📖 Read
via "Dark Reading".
The first Gula Tech Foundation competitive grant program will focus on increasing African American engagement in cybersecurity.📖 Read
via "Dark Reading".
Dark Reading
Gula Tech Foundation to Award $1M in Grants to Infosec Nonprofits
The first Gula Tech Foundation competitive grant program will focus on increasing African American engagement in cybersecurity.
🕴 Why Compliance Is No Longer King for Financial Services Cybersecurity 🕴
📖 Read
via "Dark Reading".
Financial services companies' experience in risk management serves them well when it comes to minimizing their cyber-risk.📖 Read
via "Dark Reading".
Dark Reading
Why Compliance Is No Longer King for Financial Services Cybersecurity
Financial services companies' experience in risk management serves them well when it comes to minimizing their cyber-risk.
❌ The Remote-Work Transition Shifts Demand for Cyber Skills ❌
📖 Read
via "Threat Post".
According to Cyberseek, an interactive mapping tool that tracks the current state of the security job market, there are more than half a million open cybersecurity positions available in the U.S. alone (522,000).📖 Read
via "Threat Post".
Threat Post
The Remote-Work Transition Shifts Demand for Cyber Skills
According to Cyberseek, there are more than half a million open cybersecurity positions available in the U.S. alone (522,000).
🕴 Dragos Nets $110M in Series C Led by Major Global Energy, Manufacturing, Oil & Gas Company Investors 🕴
📖 Read
via "Dark Reading".
National Grid Partners, Saudi Aramco Energy Ventures, and Hewlett Packard Enterprise led the latest funding round for the ICS/OT security company.📖 Read
via "Dark Reading".
Dark Reading
Dragos Nets $110M in Series C Led by Major Global Energy, Manufacturing, Oil & Gas Company Investors
National Grid Partners, Saudi Aramco Energy Ventures, and Hewlett Packard Enterprise led the latest funding round for the ICS/OT security company.
❌ Apple Manufacturer Foxconn Confirms Cyberattack ❌
📖 Read
via "Threat Post".
Manufacturing powerhouse confirmed North American operations impacted by November cyberattack.📖 Read
via "Threat Post".
Threat Post
Apple Manufacturer Foxconn Confirms Cyberattack
Manufacturing powerhouse confirmed North American operations impacted by November cyberattack.
❌ Microsoft Wraps Up a Lighter Patch Tuesday for the Holidays ❌
📖 Read
via "Threat Post".
Nine critical bugs and 58 overall fixes mark the last scheduled security advisory of 2020.📖 Read
via "Threat Post".
Threat Post
Microsoft Wraps Up a Lighter Patch Tuesday for the Holidays
Nine critical bugs and 58 overall fixes mark the last scheduled security advisory of 2020.
❌ Divers Pull Rare Surviving WWII Enigma Cipher Machine from Bottom of the Baltic ❌
📖 Read
via "Threat Post".
This sealogged Nazi machine will undergo restoration.📖 Read
via "Threat Post".
Threat Post
Divers Pull Rare Surviving WWII Enigma Cipher Machine from Bottom of the Baltic
This sealogged Nazi machine will undergo restoration.
‼ CVE-2020-10016 ‼
📖 Read
via "National Vulnerability Database".
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. An application may be able to execute arbitrary code with kernel privileges.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-9954 ‼
📖 Read
via "National Vulnerability Database".
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 7.0, tvOS 14.0, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Playing a malicious audio file may lead to arbitrary code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-10004 ‼
📖 Read
via "National Vulnerability Database".
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-14205 ‼
📖 Read
via "National Vulnerability Database".
The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-9974 ‼
📖 Read
via "National Vulnerability Database".
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A malicious application may be able to determine kernel memory layout.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-10009 ‼
📖 Read
via "National Vulnerability Database".
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sandbox restrictions.📖 Read
via "National Vulnerability Database".