πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2017-17060

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-15652

Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of imagemagick also use libga, so it was affected as well.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-15030

Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-15029

Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Russian Nation-State Hacking Unit's Tools Get More Fancy πŸ•΄

APT28/Fancy Bear has expanded its repertoire to more than 30 commands for infecting systems, executing code, and reconnaissance, researchers have found.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Microsoft Opens Defender ATP for Mac to Public Preview πŸ•΄

Users of the security platform who have preview features enabled can access Defender ATP for Mac via the Security Center onboarding section.

πŸ“– Read

via "Dark Reading: ".
πŸ” GDPR fines levied so far: The lessons businesses can learn πŸ”

After one year of enforcement of the GDPR, businesses can learn much from how the provisions of the regulation have been applied and how organizations have been fined.

πŸ“– Read

via "Security on TechRepublic".
πŸ” NYDFS Tasks New Cybersecurity Division to Enforce Cybersecurity Regulation πŸ”

With a new cybersecurity team dedicated to enforcing the department’s regulations under its wing, the New York Department of Financial Services (NYDFS) will grow even more vigilant of violations.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2017-13668

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-11740

In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-11739

In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was added. An attacker can abuse this functionality by creating a "Utility Widget" that contains malicious JavaScript code, aka XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-11738

In Zoho ManageEngine Application Manager 13.1 Build 13100, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-11561

An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Google's Origin & the Danger of Link Sharing πŸ•΄

How the act of sharing links to files stored in a public cloud puts organizations at risk, and what security teams can do to safeguard data and PII.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Mobile Exploit Fingerprints Devices with Sensor Calibration Data πŸ•΄

Data from routines intended to calibrate motion sensors can identify individual iOS and Android devices in a newly released exploit.

πŸ“– Read

via "Dark Reading: ".
❌ Calibration Attack Drills Down on iPhone, Pixel Users ❌

A new way of tracking mobile users creates a globally unique device fingerprint that browsers and other protections can't stop.

πŸ“– Read

via "Threatpost".
❌ Shade Ransomware Expands to U.S. Targets ❌

Coming to America: The Shade ransomware, which has historically targeted Russian victims, was recently spotted expanding its sights.

πŸ“– Read

via "Threatpost".
πŸ•΄ FEC Gives Green Light for Free Cybersecurity Help in Federal Elections πŸ•΄

Official opinion issued by the Federal Election Commission to nonprofit Defending Digital Campaigns is good news for free and reduced-cost security offerings to political candidates and committees.

πŸ“– Read

via "Dark Reading: ".
❌ Goodbye Passwords: Hello Identity Management ❌

As passwords are increasingly viewed as security liabilities, Identity Management solutions are picking up the slack.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-13667

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-11560

An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.

πŸ“– Read

via "National Vulnerability Database".