🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2020-28479

The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.

📖 Read

via "National Vulnerability Database".
🕴 The Most Pressing Concerns Facing CISOs Today 🕴

Building security into the software development life cycle creates more visibility, but CISOs still need stay on top of any serious threats on the horizon, even if they are largely unknown.

📖 Read

via "Dark Reading".
🦿 CES 2021: All of the business tech news you need to know 🦿

Don't miss TechRepublic's CES 2021 coverage, which includes product announcements from Lenovo, Samsung, LG, and Dell about PCs, laptops, software, robots, monitors, and TVs.

📖 Read

via "Tech Republic".
🦿 How to enable enhanced randomize MAC addresses on Android 🦿

Android 11 allows users to enable the Wi-Fi-Enhanced MAC randomization. Jack Wallen shows you how.

📖 Read

via "Tech Republic".
🦿 Politics and online privacy: How American Republicans and Democrats differ, and where they agree 🦿

A report from NordVPN finds disagreement on which political leader does better on privacy issues, whether disinformation should be banned, and what the biggest cyberthreat is.

📖 Read

via "Tech Republic".
🦿 CES 2021: All of the business tech news you need to know 🦿

Don't miss TechRepublic's CES 2021 coverage, which includes product announcements from Lenovo, Samsung, LG, and Dell about PCs, laptops, software, robots, monitors, and TVs.

📖 Read

via "Tech Republic".
🦿 10 trends shaping the security industry in 2021 🦿

Increased use of edge computing could "put AI everywhere," according to Hikvision's trends roundup.

📖 Read

via "Tech Republic".
🦿 FBI warns of voice phishing attacks targeting employees at large companies 🦿

Using VoIP calls, the attackers trick people into logging into phishing sites as a way to steal their usernames and passwords.

📖 Read

via "Tech Republic".
CVE-2020-27270

SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows unauthenticated physically proximate attacker to sniff keys via (BLE).

📖 Read

via "National Vulnerability Database".
CVE-2021-20190

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

📖 Read

via "National Vulnerability Database".
CVE-2020-27272

SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the keys and spoof the pump via BLE.

📖 Read

via "National Vulnerability Database".
CVE-2020-8581

Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.

📖 Read

via "National Vulnerability Database".
CVE-2020-27276

SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the communicating entities before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the authentication sequence via Bluetooth Low Energy.

📖 Read

via "National Vulnerability Database".
CVE-2020-35929

In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.

📖 Read

via "National Vulnerability Database".
🔏 $332 Million in GDPR Fines Issued to Date 🔏

The figure, about 272.5 million euros, corresponds to 281,000 data breach notifications issued by regulators across Europe since GDPR went into effect.

📖 Read

via "Digital Guardian".
Rob Joyce to Take Over as NSA Cybersecurity Director

Joyce will replace Anne Neuberger, who is now deputy national security advisor for the incoming Biden administration.

📖 Read

via "Threat Post".
🕴 4 Intriguing Email Attacks Detected by AI in 2020 🕴

Here's to the sneakiest of the sneaky. These clever phishing messages -- that standard validation measures often missed -- deserve proper dishonor.

📖 Read

via "Dark Reading".
CVE-2021-21263

Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this will simply lead to no results being returned by the query builder; however, it is possible certain queries could be affected in a way that causes the query to return unexpected results.

📖 Read

via "National Vulnerability Database".
CVE-2020-14409

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

📖 Read

via "National Vulnerability Database".
CVE-2020-14410

SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.

📖 Read

via "National Vulnerability Database".
DNSpooq Flaws Allow DNS Hijacking of Millions of Devices

Seven flaws in open-source software Dnsmasq could allow DNS cache poisoning attacks and remote code execution.

📖 Read

via "Threat Post".