πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2016-10745

In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

πŸ“– Read

via "National Vulnerability Database".
πŸ” How to protect your business from tax fraud πŸ”

With the April 15th filing deadline around the corner, cybercriminals are counting on a rushed response to questions to infect potential victims.

πŸ“– Read

via "Security on TechRepublic".
❌ Spam Campaigns Spread TrickBot Malware with Tax Lure ❌

Three recent spam campaigns are pretending to be from ADP and Paychex; in reality, the malicious emails are spreading the TrickBot trojan.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-7912

Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-9186

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code execution. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-5436

A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to possible information disclosure. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-5435

An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Products Under EU Investigation About Data Collection πŸ•΄

A new inquiry aims to determine whether contracts between Microsoft and EU organizations violate GDPR.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 8 Steps to More Effective Small Business Security πŸ•΄

Small business face the same security challenges as large enterprises but with much smaller security teams. Here are 8 things to do to get the most from yours.

πŸ“– Read

via "Dark Reading: ".
❌ New Mirai Samples Grow the Number of Processors Targets ❌

Researchers said that they discovered new Mirai samples in February 2019, capable of infecting devices powered by a broadened range of processors.

πŸ“– Read

via "Threatpost".
❌ TP-Link Routers Vulnerable to Zero-Day Buffer Overflow Attack ❌

Consumer router models allowed authenticated users to take unrestricted remote control over TL-WR940N and TL-WR941ND routers.

πŸ“– Read

via "Threatpost".
πŸ•΄ Credential-Stuffing Attacks Behind 30 Billion Login Attempts in 2018 πŸ•΄

Using e-mail addresses and passwords from compromised sites, attackers most often targeted retail sites, video-streaming services, and entertainment companies, according to Akamai.

πŸ“– Read

via "Dark Reading: ".
πŸ” Introducing the New Digital Guardian Support Community πŸ”

Digital Guardian upgraded its Support Community over the weekend to provide an improved user experience, better workflows and ticketing process.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ 'Exodus' iOS Surveillance Software Masqueraded as Legit Apps πŸ•΄

Italian firm appears to have developed spyware for lawful intercept purposes, Lookout says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 20 Million Dollar Investment Round Shows Growth of Risk Assessment Market πŸ•΄

The Series B investment supports a company bringing risk assessment to businesses in business terms.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 20 Million Dollar Investment Round Shows Growth of Risk Assessment Market πŸ•΄

The Series B investment supports a company bringing risk assessment to businesses in business terms.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Guilty Plea in Senate Data Theft πŸ•΄

A former senate staff member stole personal information about three senators and published it on Wikipedia.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 'Digital Doppelganger' Underground Takes Payment Card Theft to the Next Level πŸ•΄

Massive criminal marketplace discovered packaging and selling stolen credentials along with victims' online behavior footprints.

πŸ“– Read

via "Dark Reading: ".
❌ SAS 2019: Genesis Marketplace Peddles 60K Stolen Digital Identities ❌

An underground marketplace is selling tens of thousands of compromised digital identities, paving the way for cybercriminals to commit online fraud.

πŸ“– Read

via "Threatpost".
⚠ Fired sysadmin pleads guilty to doxxing five senators on Wikipedia ⚠

Cosko, 27, pleaded guilty to five counts including making public restricted personal information, computer fraud, witness tampering and obstruction of justice,

πŸ“– Read

via "Naked Security".
⚠ Hacker unlocks Samsung S10 with 3D-printed fingerprint ⚠

According to a video posted on the Imgur site Friday, it’s possible to bypass the biometrics on the new Galaxy S10 range using a 3D-printed fingerprint in minutes.

πŸ“– Read

via "Naked Security".