πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ State-sponsored Threat Groups Target Telcos, Steal 5G Secrets ❌

Researchers say China-linked APTs lure victims with bogus Huawei career pages in what they dub β€˜Operation DiΓ nxΓΉn’.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-14358 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35456 β€Ό

The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because of excessive logging.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35455 β€Ό

The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28660 β€Ό

rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35454 β€Ό

The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20200 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
❌ Mimecast: SolarWinds Attackers Stole Source Code ❌

A new Mimecast update reveals the SolarWinds hackers accessed several "limited" source code repositories.

πŸ“– Read

via "Threat Post".
πŸ•΄ COVID, Healthcare Data & the Dark Web: A Toxic Stew πŸ•΄

The growing treasure trove of healthcare data is proving irresistible -- and profitable -- to bad actors.

πŸ“– Read

via "Dark Reading".
⚠ Bitcoin scammer who hacked celeb Twitter accounts gets 3 years ⚠

Youngster behind blue-flag Twitter hack of Elon Musk, Bill Gates, Apple Inc. and many others will do three years in prison.

πŸ“– Read

via "Naked Security".
❌ $4,000 COVID-19 β€˜Relief Checks’ Cloak Dridex Malware ❌

The American Rescue Act is the latest zeitgeisty lure being circulated in an email campaign.

πŸ“– Read

via "Threat Post".
πŸ” FBI Warns of PYSA Ransomware Targeting Educational Sector πŸ”

The FBI provided technical details on the ransomware strain along with indicators of compromise and domains associated with its activity on Tuesday.

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Teen Behind Twitter Hack Agrees to Three Years in Prison πŸ•΄

Graham Ivan Clark was 17 when accused of the attack that targeted several high-profile Twitter accounts.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA Urges Caution on Trickbot Campaigns πŸ•΄

Advisory warns security teams to guard against advanced Trojan malware.

πŸ“– Read

via "Dark Reading".
🦿 Beware of stalkerware: Stalkers use it to track your every move 🦿

Kaspersky warns that with a stalkerware app, another person can spy on your activities and view your personal information.

πŸ“– Read

via "Tech Republic".
🦿 Crimeware-as-a-service is the latest ransomware threat 🦿

BlackBerry researchers see more double-extortion ransomware attacks, attackers demanding ransom from healthcare patients, and rising bitcoin prices driving the growth of ransomware.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-17457 β€Ό

Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The payload is triggered in the HTTP error response pages.

πŸ“– Read

via "National Vulnerability Database".
🦿 What consumers really think of the upcoming IDFA opt-in, protecting privacy and smartphone data 🦿

App developers need to implement workarounds and create an understanding of the benefits of shared data, according to a new survey from AppsFlyer and Mobile Marketing Association.

πŸ“– Read

via "Tech Republic".
🦿 More than 16 million COVID-themed cyberattacks launched in 2020 🦿

A Trend Micro report found that its system dealt with 16.4 million threats that used COVID-19 as a hook.

πŸ“– Read

via "Tech Republic".
🦿 Eternal Terminal: How to install for persistent SSH connections 🦿

If you have trouble with SSH connections breaking, Jack Wallen shows you how you can enjoy a bit more persistence with the help of Eternal Terminal.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2019-18235 β€Ό

Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.

πŸ“– Read

via "National Vulnerability Database".