πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2017-14852

An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-14851

A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack allows for authentication bypass.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-14850

All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with access to the web interface is able to hijack sessions or navigate victims outside of SiteOmat, to a malicious server owned by him.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-14728

An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication open to public.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Baltimore Ransomware Attacker Was Behind Now-Suspended Twitter Account πŸ•΄

Researchers at Armor were able to confirm the person or persons behind a Twitter account that appeared to be leaking confidential files was the actual ransomware attacker that hit the city.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Microsoft Urges Businesses to Patch 'BlueKeep' Flaw πŸ•΄

Fearing another worm of WannaCry severity, Microsoft warns vulnerable users to apply the software update for CVE-2019-0708.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-14854

A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vulnerability affects all versions prior to 2017-09-25.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Zebrocy APT Group Expands Malware Arsenal with New Backdoor Family πŸ•΄

Group's constant experimentation and malware changes are complicating efforts for defenders, Kaspersky Lab says.

πŸ“– Read

via "Dark Reading: ".
⚠ Apple sunsets iTunes ⚠

RIP iTunes, hello to the standalone Music, Podcasts and TV apps that are taking its place.

πŸ“– Read

via "Naked Security".
❌ Infosecurity Europe: Cryptojacking is Making a Comeback ❌

At Infosecurity Europe, a security expert from Guardicore discusses a new cryptomining malware campaign called Nanshou and why the cryptojacking threat is set to get worse.

πŸ“– Read

via "Threatpost".
⚠ US visa applicants required to hand over social media info ⚠

As of Friday, it's no longer optional - the US is been asking for five years of social media information.

πŸ“– Read

via "Naked Security".
⚠ GandCrab ransomware service shuts up shop ⚠

The authors of the GandCrab ransomware strain are shutting their ransomware-as-a-service portal, allegedly walking away with a cool $150m.

πŸ“– Read

via "Naked Security".
⚠ Synthetic clicks and the macOS flaw Apple can’t seem to fix ⚠

A researcher has found a way to abuse synthetic clicks in macOS "Catalina", and it hasn’t even shipped yet.

πŸ“– Read

via "Naked Security".
πŸ” Employees are almost as dangerous to business security as hackers and cybercriminals πŸ”

Non-malicious insiders are among the top three threat actors, according to an ISACA report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to protect your customers' personal identifiable information πŸ”

Personal identifiable information (PII) was the leading type of data breach in 2018, accounting for 97% of all breaches, according to a ForgeRock report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ What Cyber Skills Shortage? πŸ•΄

Employers can solve the skills gap by first recognizing that there isn't an archetypal "cybersecurity job" in the same way that there isn't an archetypal "automotive job." Here's how.

πŸ“– Read

via "Dark Reading: ".
❌ A New Approach for Combating Insider Threats ❌

Threat detection tools don't take into account the emotional aspect of insider threats, a panel of experts said at Infosecurity Europe this week.

πŸ“– Read

via "Threatpost".
πŸ•΄ Imperva Snaps Up Distil Networks for API, App Security πŸ•΄

Distil Networks' technology will be integrated into Imperva's security stack following the acquisition.

πŸ“– Read

via "Dark Reading: ".
❌ AI Isn’t Good Enough When Lives Are on the Line, Experts Warn ❌

During Infosecurity Europe in London this week, cybersecurity experts sounded off on worries about artificial intelligence being used for nation state cyber weapons.

πŸ“– Read

via "Threatpost".
πŸ•΄ Medical Debt Collector Breach Highlights Supply Chain Dangers πŸ•΄

The breach of the website of American Medical Collection Agency leaves the personal and financial information of nearly 12 million patients at risk.

πŸ“– Read

via "Dark Reading: ".
πŸ” GandCrab Ransomware Gang Calling It Quits πŸ”

The cybercriminals are reportedly winding down operations around the ransomware after claiming to have made $2 billion in ransom payments

πŸ“– Read

via "Subscriber Blog RSS Feed ".