πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-28133 β€Ό

An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26405 β€Ό

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28138 β€Ό

SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28136 β€Ό

An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13348 β€Ό

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

πŸ“– Read

via "National Vulnerability Database".
❌ ThreatList: Pharma Mobile Phishing Attacks Turn to Malware ❌

After the breakout of the COVID-19 pandemic, mobile phishing attacks targeting pharmaceutical companies have shifted their focus from credential theft to malware delivery.

πŸ“– Read

via "Threat Post".
❌ Defining Security Policies to Manage Remote Insider Threats ❌

This is the time to define the new normal; having well-defined policies in place will help businesses maintain its security posture while bolstering the security of the ever-increasing work-from-home population.

πŸ“– Read

via "Threat Post".
πŸ•΄ Vulnerability Prioritization Tops Security Pros' Challenges πŸ•΄

Why vulnerability prioritization has become a top challenge for security professionals and how security and development teams can get it right.

πŸ“– Read

via "Dark Reading".
❌ Multiple Industrial Control System Vendors Warn of Critical Bugs ❌

Four industrial control system vendors each announced vulnerabilities that ranged from critical to high-severity.

πŸ“– Read

via "Threat Post".
πŸ•΄ EFF, Security Experts Condemn Politicization of Election Security πŸ•΄

Open letter, signed by high-profile security professionals and organizations, urges White House to "reverse course and support election security."

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-26551 β€Ό

An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28129 β€Ό

Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php?page=packages via vulnerable fields 'Package Name' and 'Description'.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26549 β€Ό

An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28915 β€Ό

A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.

πŸ“– Read

via "National Vulnerability Database".
❌ Firing of CISA Chief Christopher Krebs Widely Condemned ❌

President Trump fired US cybersecurity chief over Twitter Tuesday, an act widely condemned within the cybersecurity community.

πŸ“– Read

via "Threat Post".
🦿 Microsoft's new security chip takes PC protection to a higher level 🦿

Intel, AMD and Qualcomm will use the Microsoft-designed Pluton security processor from Xbox One and Azure Sphere in future SoCs to deliver better protection than a TPM.

πŸ“– Read

via "Tech Republic".
🦿 Zoom: These new features will prevent trolls and meeting-crashers 🦿

Zoom hosts can now pause a meeting while they remove a disruptive participant, and a new web-scanning tool will seek out compromised meeting links.

πŸ“– Read

via "Tech Republic".
🦿 "123456" tops list of most common passwords for 2020 🦿

People are still using very simple passwords, with many of them similar to the ones they used in 2019, according to NordPass.

πŸ“– Read

via "Tech Republic".
🦿 How to improve the security of your public cloud 🦿

Almost all the professionals who responded to a survey from BitGlass were concerned about the security of their public cloud apps and data.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Researchers Say They've Developed Fastest Open Source IDS/IPS πŸ•΄

With a five-processor core, "Pigasus" delivers the same performance as a system with between 100 and 700 cores, according to a team from Carnegie Mellon University's CyLab.

πŸ“– Read

via "Dark Reading".
⚠ Sophos 2021 Threat Report: Navigating cybersecurity in an uncertain world ⚠

Here's the latest Sophos Threat Report - learn what cybercriminals are up to on Windows, Linux, Android and more

πŸ“– Read

via "Naked Security".