πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-13348 β€Ό

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

πŸ“– Read

via "National Vulnerability Database".
❌ ThreatList: Pharma Mobile Phishing Attacks Turn to Malware ❌

After the breakout of the COVID-19 pandemic, mobile phishing attacks targeting pharmaceutical companies have shifted their focus from credential theft to malware delivery.

πŸ“– Read

via "Threat Post".
❌ Defining Security Policies to Manage Remote Insider Threats ❌

This is the time to define the new normal; having well-defined policies in place will help businesses maintain its security posture while bolstering the security of the ever-increasing work-from-home population.

πŸ“– Read

via "Threat Post".
πŸ•΄ Vulnerability Prioritization Tops Security Pros' Challenges πŸ•΄

Why vulnerability prioritization has become a top challenge for security professionals and how security and development teams can get it right.

πŸ“– Read

via "Dark Reading".
❌ Multiple Industrial Control System Vendors Warn of Critical Bugs ❌

Four industrial control system vendors each announced vulnerabilities that ranged from critical to high-severity.

πŸ“– Read

via "Threat Post".
πŸ•΄ EFF, Security Experts Condemn Politicization of Election Security πŸ•΄

Open letter, signed by high-profile security professionals and organizations, urges White House to "reverse course and support election security."

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-26551 β€Ό

An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28129 β€Ό

Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php?page=packages via vulnerable fields 'Package Name' and 'Description'.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26549 β€Ό

An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28915 β€Ό

A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.

πŸ“– Read

via "National Vulnerability Database".
❌ Firing of CISA Chief Christopher Krebs Widely Condemned ❌

President Trump fired US cybersecurity chief over Twitter Tuesday, an act widely condemned within the cybersecurity community.

πŸ“– Read

via "Threat Post".
🦿 Microsoft's new security chip takes PC protection to a higher level 🦿

Intel, AMD and Qualcomm will use the Microsoft-designed Pluton security processor from Xbox One and Azure Sphere in future SoCs to deliver better protection than a TPM.

πŸ“– Read

via "Tech Republic".
🦿 Zoom: These new features will prevent trolls and meeting-crashers 🦿

Zoom hosts can now pause a meeting while they remove a disruptive participant, and a new web-scanning tool will seek out compromised meeting links.

πŸ“– Read

via "Tech Republic".
🦿 "123456" tops list of most common passwords for 2020 🦿

People are still using very simple passwords, with many of them similar to the ones they used in 2019, according to NordPass.

πŸ“– Read

via "Tech Republic".
🦿 How to improve the security of your public cloud 🦿

Almost all the professionals who responded to a survey from BitGlass were concerned about the security of their public cloud apps and data.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Researchers Say They've Developed Fastest Open Source IDS/IPS πŸ•΄

With a five-processor core, "Pigasus" delivers the same performance as a system with between 100 and 700 cores, according to a team from Carnegie Mellon University's CyLab.

πŸ“– Read

via "Dark Reading".
⚠ Sophos 2021 Threat Report: Navigating cybersecurity in an uncertain world ⚠

Here's the latest Sophos Threat Report - learn what cybercriminals are up to on Windows, Linux, Android and more

πŸ“– Read

via "Naked Security".
πŸ•΄ How to Identify Cobalt Strike on Your Network πŸ•΄

Common antivirus systems frequently miss Cobalt Strike, a stealthy threat emulation toolkit admired by red teams and attackers alike.

πŸ“– Read

via "Dark Reading".
🦿 Security experts level criticism at Apple after Big Sur launch issues 🦿

Users took to social media to complain about slow systems with one report pointing to an OCSP responder as the culprit.

πŸ“– Read

via "Tech Republic".
🦿 66% of companies say it would take 5 or more days to fully recover from a ransomware attack ransom not paid 🦿

Veritas research finds data protection strategies are not keeping pace with the complexity of the attacks enterprises are facing.

πŸ“– Read

via "Tech Republic".
🦿 How remote working poses security risks for your organization 🦿

Companies are at greater risk due to phishing attacks, password sharing, and unsecured personal devices, says SailPoint.

πŸ“– Read

via "Tech Republic".