πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Mac Attackers Remain Focused Mainly on Adware, Fooling Users πŸ•΄

Despite reports that Macs have encountered more threats than Windows systems, the platform still sees far fewer exploits and malware - including ransomware.

πŸ“– Read

via "Dark Reading".
❌ 2020 Work-for-Home Shift: What We Learned ❌

Threatpost explores 5 big takeaways from 2020 -- and what they mean for 2021.

πŸ“– Read

via "Threat Post".
🦿 How companies can use automation to secure cloud data 🦿

Data automation allows companies to conduct operations more consistently, securely, and reliably. Learn how one company tackled the challenges.

πŸ“– Read

via "Tech Republic".
πŸ•΄ India: A Growing Cybersecurity Threat πŸ•΄

Geopolitical tensions and a dramatic rise in offensive and defensive cyber capabilities lead India to join Iran, Russia, China, and North Korea as a top nation-state adversary.

πŸ“– Read

via "Dark Reading".
❌ Japanese Aerospace Firm Kawasaki Warns of Data Breach ❌

The Japanese aerospace manufacturer said that starting in June, overseas unauthorized access to its servers may have compromised customer data.

πŸ“– Read

via "Threat Post".
❌ 6 Questions Attackers Ask Before Choosing an Asset to Exploit ❌

David β€œmoose” Wolpoff at Randori explains how hackers pick their targets, and how understanding "hacker logic" can help prioritize defenses.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-5801 β€Ό

An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5802 β€Ό

An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5806 β€Ό

An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5807 β€Ό

An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer (FTDiagViewer.exe) to view the log entry. Observed in FactoryTalk Diagnostics 6.11. All versions of FactoryTalk Diagnostics are affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29475 β€Ό

nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time any user will go to that page of the website, the XSS triggers and attacker can able to steal the cookie according to the crafted payload.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Reducing the Risk of Third-Party SaaS Apps to Your Organization πŸ•΄

Such apps may try to leak your data, or can contain malicious code. And even legitimate apps may be poorly written, creating security risks.

πŸ“– Read

via "Dark Reading".
πŸ›  OATH Toolkit 2.6.5 πŸ› 

OATH Toolkit attempts to collect several tools that are useful when deploying technologies related to OATH, such as HOTP one-time passwords. It is a fork of the earlier HOTP Toolkit.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2020-35735 β€Ό

Vidyo 02-09-/D allows clickjacking via the portal/ URI.

πŸ“– Read

via "National Vulnerability Database".
❌ Lawsuit Claims Flawed Facial Recognition Led to Man’s Wrongful Arrest ❌

Black man sues police, saying he was falsely ID’d by facial recognition, joining other Black Americans falling victim to the technology’s racial bias.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-35787 β€Ό

Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.36, D7000 before 1.0.1.70, EX6200v2 before 1.0.1.78, EX7000 before 1.0.1.78, EX8000 before 1.0.1.186, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.42, R6050 before 1.0.1.18, R6080 before 1.0.0.42, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6260 before 1.1.0.64, R6300v2 before 1.0.4.34, R6700 before 1.0.2.6, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900 before 1.0.2.4, R6900P before 1.3.1.64, R6900v2 before 1.2.0.36, R7000 before 1.0.9.42, R7000P before 1.3.1.64, R7800 before 1.0.2.60, R8900 before 1.0.4.12, R9000 before 1.0.4.12, and XR500 before 2.3.2.40.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-10207 β€Ό

Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows remote attackers to retrieve and modify the device settings.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35804 β€Ό

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D7800 before 1.0.1.58, R7800 before 1.0.2.74, R8900 before 1.0.5.18, R9000 before 1.0.5.18, and XR700 before 1.0.1.34.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35793 β€Ό

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.5.2, and R9000 before 1.0.5.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35781 β€Ό

NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35780 β€Ό

NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.

πŸ“– Read

via "National Vulnerability Database".