πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2018-12300

Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12299

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12298

Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12297

Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12296

Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12295

SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Open Testing Standards Can Improve Security πŸ•΄

When creating security metrics, it's critical that test methodologies cover multiple scenarios to ensure that devices perform as expected in all environments.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to use SFTP with a chroot jail πŸ”

Lock down all SFTP users on your data center Linux servers with a chroot jail.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2012-6652

Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ ThreatList: Top 5 Most Dangerous Attachment Types ❌

From ZIP attachments spreading Gandcrab, to DOC files distributing Trickbot, researchers tracked five widescale spam campaigns in 2019 that have made use of malicious attachments.

πŸ“– Read

via "Threatpost".
❌ ScarCruft APT Adds Bluetooth Harvester to its Malware Bag of Tricks ❌

In its latest observed campaign, there were also overlaps in victimology with the DarkHotel APT.

πŸ“– Read

via "Threatpost".
πŸ•΄ 78% of Consumers Say Online Companies Must Protect Their Info πŸ•΄

Yet 68% of US consumers agree they also must do more to protect their own information.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Poorly Configured Server Exposes Most Panama Citizens' Data πŸ•΄

Compromised information includes full names, birth dates, national ID numbers, medical insurance numbers, and other personal data.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9287

Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulated by an attacker. The "kid" field is not signed like the rest of the message, and manipulation is therefore trivial. The "kid" field should only ever represent an integer. However, it is possible to provide any string value. An attacker could use this to their advantage to force the application agent to load the RSA public key required for message integrity checking from an unintended location.

πŸ“– Read

via "National Vulnerability Database".
πŸ” FTC Backs Federal Privacy Law As Long As It Can Enforce It πŸ”

The FTC told Congress last week that if a national privacy law gets passed, it wants more resources and greater authority to impose penalties under it.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Attacks on JavaScript Services Leak Info From Websites πŸ•΄

Three marketing tools, including the Best Of The Web security logomark, were compromised in supply chain attacks, allegedly leaving website customers leaking their users' sensitive information.

πŸ“– Read

via "Dark Reading: ".
❌ Twitter Leaks Apple iOS Users’ Location Data to Ad Partner ❌

A Twitter glitch "inadvertently" leaked iOS users' location data to an unnamed partner.

πŸ“– Read

via "Threatpost".
πŸ•΄ LockerGoga, MegaCortex Ransomware Share Unlikely Traits πŸ•΄

New form of ransomware MegaCortex shares commonalities with LockerGoga, enterprise malware recently seen in major cyberattacks.

πŸ“– Read

via "Dark Reading: ".
❌ Pair of Cisco Bugs, One Unpatched, Affect Millions of Devices ❌

The two high-severity bugs impact a wide array of enterprise, military and government networks.

πŸ“– Read

via "Threatpost".
πŸ•΄ Thrangrycat Claws Cisco Customer Security πŸ•΄

A linked pair of vulnerabilities could allow an attacker to take over many different types of Cisco networking components.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Korean APT Adds Rare Bluetooth Device-Harvester Tool πŸ•΄

ScarCruft has evolved into a skilled and resourceful threat group, new research shows.

πŸ“– Read

via "Dark Reading: ".