🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2020-26254

omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during authentication. This vulnerability impacts applications using the omniauth-apple strategy of OmniAuth and using the info.email field of OmniAuth's Auth Hash Schema for any kind of identification. The value of this field may be set to any value of the attacker's choice including email addresses of other users. Applications not using info.email for identification but are instead using the uid field are not impacted in the same manner. Note, these applications may still be negatively affected if the value of info.email is being used for other purposes. Applications using affected versions of omniauth-apple are advised to upgrade to omniauth-apple version 1.0.1 or later.

📖 Read

via "National Vulnerability Database".
CVE-2020-29578

The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.

📖 Read

via "National Vulnerability Database".
CVE-2020-29577

The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.

📖 Read

via "National Vulnerability Database".
Critical, Unpatched Bug Opens GE Radiological Devices to Remote Code Execution

A CISA alert is flagging a critical default credentials issue that affects 100+ types of devices found in hospitals, from MRI machines to surgical imaging.

📖 Read

via "Threat Post".
🦿 How to protect yourself from gift card scams 🦿

With the holiday season in bloom, watch out for scams that promise free gift cards or offer to check your gift card balance, says Bolster.

📖 Read

via "Tech Republic".
🦿 Linux Foundation debuts new, secure, open source cloud native access management software platform 🦿

Based on the Gluu server, the Janssen Project prioritizes security and performance and features signing and encryption functionalities.

📖 Read

via "Tech Republic".
🕴 Keeping Cyber Secure at Christmas 🕴

Sylvain Cortes, Security Evangelist and cybersecurity expert at Alsid, highlights the need for security departments to raise awareness through their organizations over cyber threats this Christmas.

📖 Read

via "Dark Reading".
🕴 Fortinet Purchases Panopta 🕴

The acquisition is intended to improve the visibility and automated response capabilities of Fortinet's Security Fabri.

📖 Read

via "Dark Reading".
🕴 Gula Tech Foundation to Award $1M in Grants to Infosec Nonprofits 🕴

The first Gula Tech Foundation competitive grant program will focus on increasing African American engagement in cybersecurity.

📖 Read

via "Dark Reading".
🕴 Why Compliance Is No Longer King for Financial Services Cybersecurity 🕴

Financial services companies' experience in risk management serves them well when it comes to minimizing their cyber-risk.

📖 Read

via "Dark Reading".
The Remote-Work Transition Shifts Demand for Cyber Skills

According to Cyberseek, an interactive mapping tool that tracks the current state of the security job market, there are more than half a million open cybersecurity positions available in the U.S. alone (522,000).

📖 Read

via "Threat Post".
🕴 Dragos Nets $110M in Series C Led by Major Global Energy, Manufacturing, Oil & Gas Company Investors 🕴

National Grid Partners, Saudi Aramco Energy Ventures, and Hewlett Packard Enterprise led the latest funding round for the ICS/OT security company.

📖 Read

via "Dark Reading".
Apple Manufacturer Foxconn Confirms Cyberattack

Manufacturing powerhouse confirmed North American operations impacted by November cyberattack.

📖 Read

via "Threat Post".
Microsoft Wraps Up a Lighter Patch Tuesday for the Holidays

Nine critical bugs and 58 overall fixes mark the last scheduled security advisory of 2020.

📖 Read

via "Threat Post".
Divers Pull Rare Surviving WWII Enigma Cipher Machine from Bottom of the Baltic

This sealogged Nazi machine will undergo restoration.

📖 Read

via "Threat Post".
CVE-2020-10016

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. An application may be able to execute arbitrary code with kernel privileges.

📖 Read

via "National Vulnerability Database".
CVE-2020-9954

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 7.0, tvOS 14.0, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Playing a malicious audio file may lead to arbitrary code execution.

📖 Read

via "National Vulnerability Database".
CVE-2020-10004

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

📖 Read

via "National Vulnerability Database".
CVE-2020-14205

The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.

📖 Read

via "National Vulnerability Database".
CVE-2020-9974

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A malicious application may be able to determine kernel memory layout.

📖 Read

via "National Vulnerability Database".
CVE-2020-10009

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sandbox restrictions.

📖 Read

via "National Vulnerability Database".