πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” UK Sees Steep Jump in Cyber Attacks on Financial Services Firms πŸ”

According to a regulator, retail banks in the region took the biggest hit last year.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Disarming Employee Weaponization πŸ•΄

Human vulnerability presents a real threat for organizations. But it's also a remarkable opportunity to turn employees into our strongest cyber warriors.

πŸ“– Read

via "Dark Reading: ".
πŸ” DevOps will fail unless security and developer teams communicate better πŸ”

DevOps initiatives have become important for 74% of organizations over the past year, but communication must improve for DevOps to be successful, according to Trend Micro.

πŸ“– Read

via "Security on TechRepublic".
❌ Amazon Admits Alexa Voice Recordings Saved Indefinitely ❌

Amazon's acknowledgment that it saves Alexa voice recordings - even sometimes after consumers manually delete their interaction history - has thrust voice assistant privacy policies into the spotlight once again.

πŸ“– Read

via "Threatpost".
⚠ Serious Security: Beware eBay scrapers promising to help you with β€˜viral promotions’ ⚠

Selling items online? Watch our for people who suddenly offer to help!

πŸ“– Read

via "Naked Security".
πŸ” Amazon Prime Day, EA gaming service's vulnerabilities, and the basics of multicloud πŸ”

This week's TechRepublic and ZDNet news stories include the brand battle between Apple and Microsoft, Word documents containing malicious links, and the future of on-premises databases.

πŸ“– Read

via "Security on TechRepublic".
❌ Apple Transparency Report Now Includes App Store Takedown Requests ❌

Apple report now includes data on requests by governments to take down apps from the tech giant's app store.

πŸ“– Read

via "Threatpost".
πŸ” Tech news roundup: Amazon Prime Day, EA gaming service's vulnerabilities, and the basics of multicloud πŸ”

This week's TechRepublic and ZDNet news stories include the brand battle between Apple and Microsoft, Word documents containing malicious links, and the future of on-premises databases.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-11427

CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11426

A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute force parameters required to bypass authentication and access the web interface to use all its functions except for password change.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 20 Questions to Ask During a Real (or Manufactured) Security Crisis πŸ•΄

There are important lessons to be learned from a crisis, even the ones that are more fiction than fact.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ More Than Half of SMB Devices Run Outdated Operating Systems πŸ•΄

66% of devices in small-to midsized businesses are based on expired or about-to-expire Microsoft OS versions, Alert Logic study found.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Sodin Ransomware Exploits Windows Privilege Escalation Bug πŸ•΄

Exploitation of CVE-2018-8453 grants attackers the highest level of privileges on a target system.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-9327

Secret data of processes managed by CM is not secured by file permissions.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-9326

The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-agent directory managed by Cloudera Manager. The keystore file itself is not exposed.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-9325

The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-6900

An issue was discovered in Riello NetMan 204 14-2 and 15-2. The issue is with the login script and wrongpass Python script used for authentication. When calling wrongpass, the variables $VAL0 and $VAL1 should be enclosed in quotes to prevent the potential for Bash command injection. Further to this, VAL0 and VAL1 should be sanitised to ensure they do not contain malicious characters. Passing it the username of '-' will cause it to time out and log the user in because of poor error handling. This will log the attacker in as an administrator where the telnet / ssh services can be enabled, and the credentials for local users can be reset. Also, login.cgi accepts the username as a GET parameter, so login can be achieved by browsing to the /cgi-bin/login.cgi?username=-%20a URI.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-6216

novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18346

SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-17972

packages/subjects/pub/subjects.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?subjecttypeid=xxx request, aka Open Bug Bounty ID OBB-466362.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ New 'WannaHydra' Malware a Triple Threat to Android πŸ•΄

The latest variant of WannaLocker is a banking Trojan, spyware tool, and ransomware.

πŸ“– Read

via "Dark Reading: ".