‼ CVE-2020-27270 ‼
📖 Read
via "National Vulnerability Database".
SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows unauthenticated physically proximate attacker to sniff keys via (BLE).📖 Read
via "National Vulnerability Database".
‼ CVE-2021-20190 ‼
📖 Read
via "National Vulnerability Database".
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27272 ‼
📖 Read
via "National Vulnerability Database".
SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the keys and spoof the pump via BLE.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-8581 ‼
📖 Read
via "National Vulnerability Database".
Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27276 ‼
📖 Read
via "National Vulnerability Database".
SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the communicating entities before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the authentication sequence via Bluetooth Low Energy.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35929 ‼
📖 Read
via "National Vulnerability Database".
In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.📖 Read
via "National Vulnerability Database".
🔏 $332 Million in GDPR Fines Issued to Date 🔏
📖 Read
via "Digital Guardian".
The figure, about 272.5 million euros, corresponds to 281,000 data breach notifications issued by regulators across Europe since GDPR went into effect.📖 Read
via "Digital Guardian".
Digital Guardian
$332 Million in GDPR Fines Issued to Date
The figure, about 272.5 million euros, corresponds to 281,000 data breach notifications issued by regulators across Europe since GDPR went into effect.
❌ Rob Joyce to Take Over as NSA Cybersecurity Director ❌
📖 Read
via "Threat Post".
Joyce will replace Anne Neuberger, who is now deputy national security advisor for the incoming Biden administration.📖 Read
via "Threat Post".
Threat Post
Rob Joyce to Take Over as NSA Cybersecurity Director
Joyce will replace Anne Neuberger, who is now deputy national security advisor for the incoming Biden administration.
🕴 4 Intriguing Email Attacks Detected by AI in 2020 🕴
📖 Read
via "Dark Reading".
Here's to the sneakiest of the sneaky. These clever phishing messages -- that standard validation measures often missed -- deserve proper dishonor.📖 Read
via "Dark Reading".
Dark Reading
4 Intriguing Email Attacks Detected by AI in 2020
Here's to the sneakiest of the sneaky. These clever phishing messages -- that standard validation measures often missed -- deserve proper dishonor.
(Sponsored)
(Sponsored)
‼ CVE-2021-21263 ‼
📖 Read
via "National Vulnerability Database".
Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this will simply lead to no results being returned by the query builder; however, it is possible certain queries could be affected in a way that causes the query to return unexpected results.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-14409 ‼
📖 Read
via "National Vulnerability Database".
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-14410 ‼
📖 Read
via "National Vulnerability Database".
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.📖 Read
via "National Vulnerability Database".
❌ DNSpooq Flaws Allow DNS Hijacking of Millions of Devices ❌
📖 Read
via "Threat Post".
Seven flaws in open-source software Dnsmasq could allow DNS cache poisoning attacks and remote code execution.📖 Read
via "Threat Post".
Threat Post
DNSpooq Flaws Allow DNS Hijacking of Millions of Devices
Seven flaws in open-source software Dnsmasq could allow DNS cache poisoning attacks and remote code execution.
🕴 SolarWinds Attack Underscores 'New Dimension' in Cyber-Espionage Tactics 🕴
📖 Read
via "Dark Reading".
Meanwhile, Malwarebytes is the latest victim, Symantec discovers a fourth piece of malware used in the massive attack campaign, and FireEye Mandiant releases a free tool to help spot signs of the attack.📖 Read
via "Dark Reading".
Dark Reading
SolarWinds Attack Underscores 'New Dimension' in Cyber-Espionage Tactics
Meanwhile, Malwarebytes is the latest victim, Symantec discovers a fourth piece of malware used in the massive attack campaign, and FireEye Mandiant releases a free tool to help spot signs of the attack.
🕴 Microsoft to Launch 'Enforcement Mode' for Zerologon Flaw 🕴
📖 Read
via "Dark Reading".
Enforcement mode for the Netlogon Domain Controller will be enabled by default with the Feb. 9 security update.📖 Read
via "Dark Reading".
Darkreading
Microsoft to Launch 'Enforcement Mode' for Zerologon Flaw
Enforcement mode for the Netlogon Domain Controller will be enabled by default with the Feb. 9 security update.
🦿 The aftermath of the SolarWinds breach: Organizations need to be more vigilant 🦿
📖 Read
via "Tech Republic".
Security experts say organizations are, and should, implement a number of changes ranging from how they vet vendors to handling application updates.📖 Read
via "Tech Republic".
TechRepublic
The aftermath of the SolarWinds breach: Organizations need to be more vigilant
Security experts say organizations are, and should, implement a number of changes ranging from how they vet vendors to handling application updates.
🕴 Vulnerabilities in Popular DNS Software Allow Poisoning 🕴
📖 Read
via "Dark Reading".
Seven flaws in DNSMasq have limited impact, but in combination they could be chained to create a multistaged attack.📖 Read
via "Dark Reading".
Dark Reading
Vulnerabilities in Popular DNS Software Allow Poisoning
Seven flaws in DNSMasq have limited impact, but in combination they could be chained to create a multistaged attack.
‼ CVE-2020-27264 ‼
📖 Read
via "National Vulnerability Database".
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which allows unauthenticated, physically proximate attackers to brute-force the keys via Bluetooth Low Energy.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29598 ‼
📖 Read
via "National Vulnerability Database".
The My AIA SG application 1.2.6 for Android allows attackers to obtain user credentials via logcat because of excessive logging.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27269 ‼
📖 Read
via "National Vulnerability Database".
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measures, which allows unauthenticated, physically proximate attackers to replay communication sequences via Bluetooth Low Energy.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27256 ‼
📖 Read
via "National Vulnerability Database".
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to change insulin therapy settings.📖 Read
via "National Vulnerability Database".