πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Veritas Technologies adds Flex Scale to NetBackup9 for scale-out functionality 🦿

The data protection company's latest delivers new features on a simplified platform to provide customers with additional choice for deployment across edge, core, and cloud.

πŸ“– Read

via "Tech Republic".
🦿 Governors hear about the dangers of a lackluster cybersecurity response, need for FBI coordination 🦿

At a national summit, Louisiana Gov. John Bel Edwards said before his state could test a cyberattack plan, five schools were hit with ransomware.

πŸ“– Read

via "Tech Republic".
🦿 Bad actors launched an unprecedented wave of DDoS attacks in 2020 🦿

Cybersecurity firm Akamai said in a report that COVID-19 and a newfound reliance on digital tools prompted a spike.

πŸ“– Read

via "Tech Republic".
🦿 Privacy budgets soared in 2020, doubling to an average of $2.4 million 🦿

93% of organizations turned to privacy teams to help navigate the COVID-19 pandemic, a new Cisco report finds.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-4889 β€Ό

IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190971.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4949 β€Ό

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.

πŸ“– Read

via "National Vulnerability Database".
❌ Criminal, Domestic Violence Case Info Exposed in Cook County Leak ❌

Cook County, Ill., home to Chicago, has left a database exposed since at least September that contained sensitive criminal and family-court records.

πŸ“– Read

via "Threat Post".
❌ Nefilim Ransomware Gang Hits Jackpot with Ghost Account ❌

An unmonitored account belonging to a deceased employee allowed Nefilim to exfiltrate data and infiltrate systems for a month, without being noticed.

πŸ“– Read

via "Threat Post".
⚠ Ghost hack – criminals use deceased employee’s account to wreak havoc ⚠

Most companies are quick to remove ex-staff from the payroll, but often not so quick to shut down their network access.

πŸ“– Read

via "Naked Security".
πŸ•΄ Fighting the Rapid Rise of Cyber Warfare in a Changing World πŸ•΄

Global cyber warfare is a grim reality, but strong public-private relationships and security frameworks can safeguard people, institutions, and businesses.

πŸ“– Read

via "Dark Reading".
🦿 How to quickly block spam SMS in Android 🦿

Jack Wallen shows you how easy it is to block and report spam SMS messages on the Android platform.

πŸ“– Read

via "Tech Republic".
🦿 Google's new zero trust product is completely cloud native 🦿

BeyondCorp Enterprise is a scalable, agentless, end-to-end zero trust platform that lives entirely within Chrome Enterprise.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Cartoon Caption Winner: Before I Go ... πŸ•΄

And the winner of The Edge's January cartoon caption contest is ...

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2018-10348 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-10341 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-11297 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-11298 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35309 β€Ό

Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML in admin dashboard - "Categories".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-17522 β€Ό

When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these permissions are potentially extended to IP addresses outside the desired range, resulting in them being granted to clients possibly outside the CDN arcitechture.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-11302 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".