πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ›  Flawfinder 2.0.14 πŸ› 

Flawfinder searches through source code for potential security flaws, listing potential security flaws sorted by risk, with the most potentially dangerous flaws shown first. This risk level depends not only on the function, but on the values of the parameters of the function.

πŸ“– Read

via "Packet Storm Security".
πŸ›  jSQL Injection 0.83 πŸ› 

jSQL Injection is a lightweight application used to find database information from a distant server. jSQL Injection is also part of the official penetration testing distribution Kali Linux and is included in various other distributions like Pentest Box, Parrot Security OS, ArchStrike and BlackArch Linux. This is the pre-built jar release.

πŸ“– Read

via "Packet Storm Security".
❌ SolarWinds Hack Potentially Linked to Turla APT ❌

Researchers have spotted notable code overlap between the Sunburst backdoor and a known Turla weapon.

πŸ“– Read

via "Threat Post".
⚠ Naked Security Live – HTTPS: do we REALLY need it? ⚠

Here's the latest Naked Security Live video talk - watch now, and please share with your friends!

πŸ“– Read

via "Naked Security".
❌ Researcher Builds Parler Archive Amid Amazon Suspension ❌

A researcher scraped and archived public Parler posts before the conservative social networking service was taken down by Amazon, Apple and Google.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-24027 β€Ό

In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" command, when the command specifies seeking by absolute time.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24025 β€Ό

Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13559 β€Ό

A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A specially crafted packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23631 β€Ό

Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via the tongji parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26298 β€Ό

Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.

πŸ“– Read

via "National Vulnerability Database".
❌ Millions of Social Profiles Leaked by Chinese Data-Scrapers ❌

A cloud misconfig by SocialArks exposed 318 million records gleaned from Facebook, Instagram and LinkedIn.

πŸ“– Read

via "Threat Post".
🦿 CES 2021: All of the business tech news you need to know 🦿

Don't miss TechRepublic's CES 2021 coverage, which includes product announcements from Lenovo, Samsung, LG, and Dell about PCs, laptops, software, robots, monitors, and TVs.

πŸ“– Read

via "Tech Republic".
🦿 CES 2021: All of the business tech news you need to know 🦿

Don't miss TechRepublic's CES 2021 coverage, which includes product announcements from Lenovo, Samsung, LG, and Dell about PCs, laptops, software, robots, monitors, and TVs.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-26050 β€Ό

SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27637 β€Ό

The R programming languageÒ€ℒs default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-16146 β€Ό

Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Over-Sharer or Troublemaker? How to Identify Insider-Risk Personas πŸ•΄

It's past time to begin charting insider risk indicators that identify risky behavior and stop it in its tracks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security πŸ•΄

How two traditionally disparate security disciplines can be united.

πŸ“– Read

via "Dark Reading".
πŸ•΄ New Tool Sheds Light on AppleScript-Obfuscated Malware πŸ•΄

The AEVT decompiler helped researchers analyze a cryptominer campaign that used AppleScript for obfuscation and will help reverse engineers focused on other Mac OS malware.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cartoon: Shakin' It Up at the Office πŸ•΄

And the winner of our December cartoon caption contest is ...

πŸ“– Read

via "Dark Reading".
πŸ•΄ SolarWinds Hack Lessons Learned: Finding the Next Supply Chain Attack πŸ•΄

The SolarWinds supply chain compromise won't be the last of its kind. Vendors and enterprises alike must learn and refine their detection efforts to find the next such attack.

πŸ“– Read

via "Dark Reading".