🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION‼ New - CVE-2018-12204

Privilege escalation vulnerability in Platform Sample/ Silicon Reference firmware Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow privileged user to potentially execute arbitrary code via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12203

Denial of service vulnerability in Platform Sample/ Silicon Reference firmware for 8th Generation Intel Core Processor, 7th Generation Intel Core Processor may allow privileged user to potentially execute arbitrary code via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12202

Privilege escalation vulnerability in Platform Sample/ Silicon Reference firmware for 8th Generation Intel(R) Core Processor, 7th Generation Intel(R) Core Processor may allow privileged user to potentially leverage existing features via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12201

Buffer overflow vulnerability in Platform Sample / Silicon Reference firmware for 8th Generation Intel(R) Core Processor, 7th Generation Intel(R) Core Processor, Intel(R) Pentium(R) Silver J5005 Processor, Intel(R) Pentium(R) Silver N5000 Processor, Intel(R) Celeron(R) J4105 Processor, Intel(R) Celeron(R) J4005 Processor, Intel Celeron(R) N4100 Processor and Intel(R) Celeron N4000 Processor may allow privileged user to potentially execute arbitrary code via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12200

Insufficient access control in Intel(R) Capability Licensing Service before version 1.50.638.1 may allow an unprivileged user to potentially escalate privileges via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12199

Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12198

Insufficient input validation in Intel(R) Server Platform Services HECI subsystem before version SPS_E5_04.00.04.393.0 may allow privileged user to potentially cause a denial of service via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12196

Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12192

Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12191

Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12190

Insufficient input validation in Intel CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially execute arbitrary code via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12189

Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12189

Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12188

Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12187

Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via network access.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-12185

Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical access.

📖 Read

via "National Vulnerability Database".
🕴 Ransomware's New Normal 🕴

GandCrab's evolution underscores a shift in ransomware attack methods.

📖 Read

via "Dark Reading: ".
🕴 Criminals Use One Line of Code to Steal Card Data from E-Commerce Sites 🕴

New JavaScript Sniffer is similar to malware used in the Magecart campaign last year that affected over 800 sites.

📖 Read

via "Dark Reading: ".
âš  Will the next version of Android get location privacy right? âš 

Google has confirmed that improved control over location tracking is one of several new privacy features in the next version of its mobile OS, Android Q.

📖 Read

via "Naked Security".
âš  How to make DuckDuckGo your default Chrome search engine âš 

Good news for the privacy-conscious. Chrome 73, released Tuesday, now includes the DuckDuckGo search engine as an option.

📖 Read

via "Naked Security".
âš  Facebook outage coincides with (or causes?) 3m new Telegram users âš 

A worldwide, nearly day-long outage at Facebook led to Telegram having a busy, busy day.

📖 Read

via "Naked Security".