πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Microsoft Patches A Pair of Zero-Days Under Active Attack ❌

The software giant also addressed 15 critical flaws and advised on the recently disclosed Linux Kernel "SACK Panic" bug.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2018-11427 (oncell_g3150-hspa-t_firmware, oncell_g3150-hspa_firmware)

CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Patches Zero-Day Vulnerabilities Under Active Attack πŸ•΄

Microsoft issued fixes for 77 unique vulnerabilities this Patch Tuesday, including two zero-day privilege escalation vulnerabilities seen exploited in the wild.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Zoom Client for Mac Exposing Users to Serious Risks πŸ•΄

Videoconferencing software maker downplays risks and says mitigations are on the way.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Coast Guard Warns Shipping Firms of Maritime Cyberattacks πŸ•΄

A commercial vessel suffered a significant malware attack in February, prompting the US Coast Guard to issues an advisory to all shipping companies: Here be malware.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Financial Impact of Cybercrime Exceeded $45B in 2018 πŸ•΄

Cybersecurity analysts explore a range of industry research to examine trends around cyber incidents and their financial impact.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Organizations Are Adapting Authentication for Cloud Applications πŸ•΄

Companies see the changing demands of cloud identity management but are mixed in their responses to those demands.

πŸ“– Read

via "Dark Reading: ".
❌ Intel Patches High-Severity Flaw in Processor Diagnostic Tool ❌

Intel issued patches for a high-severity flaw in its processor diagnostic tool as well as a fix for a medium-severity vulnerability in its data center SSD lineup.

πŸ“– Read

via "Threatpost".
⚠ Instagram asks bullies, β€˜Are you sure you want to say that?’ ⚠

A new anti-bullying feature uses AI to recognize mean words in comments and warns users before they post them.

πŸ“– Read

via "Naked Security".
⚠ Rogue Android apps ignore your permissions ⚠

New research has revealed that apps are snooping on data such as location and unique ID number - even when users haven't given permission.

πŸ“– Read

via "Naked Security".
⚠ Two zero days and 15 critical flaws fixed in July’s Patch Tuesday ⚠

Patch Tuesday July 2019 offers fixes for a total of 77 vulnerabilities, including 15 marked critical, rounded out by two zero-day flaws.

πŸ“– Read

via "Naked Security".
πŸ” Corporate users struggle to identify phishing attacks, other security threats πŸ”

An audit of security awareness conducted by Proofpoint found that users on average answered 22% of security-related questions incorrectly.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ 10 Ways to Keep a Rogue RasPi From Wrecking Your Network πŸ•΄

A Raspberry Pi attached to the network at NASA JPL became the doorway for a massive intrusion and subsequent data loss. Here's how to keep the same thing from happening to your network.

πŸ“– Read

via "Dark Reading: ".
❌ Agent Smith Malware Infects 25M Android Phones to Push Rogue Ads ❌

Researchers say malware infects phones in order to sneak ads on devices for profit.

πŸ“– Read

via "Threatpost".
πŸ•΄ 4 Reasons Why SOC Superstars Quit πŸ•΄

Security analysts know they are a hot commodity in the enviable position of writing their own ticket. Here's how to keep them engaged, challenged, and happy.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-12626

An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12625

An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12623

An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12622

An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11423 (oncell_g3150-hspa-t_firmware, oncell_g3150-hspa_firmware)

There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior, different vulnerability than CVE-2018-11420.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11420 (oncell_g3150-hspa-t_firmware, oncell_g3150-hspa_firmware)

There is Memory corruption in the web interface of Moxa OnCell G3100-HSPA Series version 1.5 Build 17042015 and prio,r a different vulnerability than CVE-2018-11423.

πŸ“– Read

via "National Vulnerability Database".