πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-8919 β€Ό

An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Black Hat Europe: Dark Reading Video News Desk Coverage πŸ•΄

Coming to you from virtual backgrounds and beautifully curated bookcases around the world, Dark Reading brings you video interviews with the leading researchers speaking at this week's Black Hat Europe.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google Shares Cloud Security Tips πŸ•΄

Anton Chuvakin, head of solution strategy at Google Cloud Security, discusses common cloud security hurdles and how to get over them.

πŸ“– Read

via "Dark Reading".
❌ Cyber Monday is Every Monday: Securing the β€˜New Normal’ ❌

From eCommerce threats, to security concerns in connected speakers, Fortinet researchers discuss the top evolving threats of 2020, heading into the new year.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep10: Hacking iPhones, sunken Enigmas and double scams [Podcast] ⚠

Latest episode - listen now, and please tell your friends about our podcast.

πŸ“– Read

via "Naked Security".
πŸ•΄ The Line Between Physical Security & Cybersecurity Blurs as World Gets More Digital πŸ•΄

Security teams are being challenged by the connected nature of IP devices, and preventing them from being compromised by cybercriminals has become an essential part of keeping people and property safe.

πŸ“– Read

via "Dark Reading".
πŸ›  Wireshark Analyzer 3.4.1 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ 85,000 MySQL Servers Hit in Active Ransomware Campaign πŸ•΄

Attackers pressure victims into paying ransom by publishing and offering for sale data stolen in a campaign that dates back to January.

πŸ“– Read

via "Dark Reading".
❌ Critical Cisco Jabber Bug Gets Updated Fix ❌

A series of bugs, patched in September, still allow remote code execution by attackers.

πŸ“– Read

via "Threat Post".
❌ PLEASE_READ_ME Ransomware Attacks 85K MySQL Servers ❌

Ransomware actors behind the attack have breached at least 85,000 MySQL servers, and are currently selling at least compromised 250,000 databases.

πŸ“– Read

via "Threat Post".
🦿 Privacy risks persist with DIY COVID-19 contact tracing apps 🦿

Do-it-yourself apps that don't use the official API from Apple and Google raised privacy concerns due to unsecure design, says Guardsquare.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 51% of Edge Readers Plan to Pursue New Cybersecurity Certification in 2021 πŸ•΄

Demands of the "new normal" won't stop the majority of poll-takers from mastering new skills.

πŸ“– Read

via "Dark Reading".
❌ MoleRats APT Returns with Espionage Play Using Facebook, Dropbox ❌

The threat group is increasing its espionage activity in light of the current political climate and recent events in the Middle East, with two new backdoors.

πŸ“– Read

via "Threat Post".
🦿 4 security bugs discovered in games on Valve's Steam platform 🦿

The vulnerabilities in Counter Strike: Global Defensive, Dota2, and Half Life could have allowed hackers to crash the games and hijack computers, according to Check Point.

πŸ“– Read

via "Tech Republic".
🦿 How to install fail2ban on Fedora 33 for protection against unwanted logins 🦿

Jack Wallen shows you how to install and configure fail2ban on the latest release of Fedora Linux.

πŸ“– Read

via "Tech Republic".
🦿 How phishing attacks continue to exploit COVID-19 🦿

These phishing emails promise compensation, test results, and other lures about the coronavirus to trick unsuspecting users, says Armorblox.

πŸ“– Read

via "Tech Republic".
❌ Misery of Ransomware Hits Hospitals the Hardest ❌

Ransomware attacks targeting hospitals have exacted a human cost as well as financial.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-8920 β€Ό

An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-8919 β€Ό

An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Black Hat Europe: Dark Reading Video News Desk Coverage πŸ•΄

Coming to you from virtual backgrounds and beautifully curated bookcases around the world, Dark Reading brings you video interviews with the leading researchers speaking at this week's Black Hat Europe.

πŸ“– Read

via "Dark Reading".