πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2018-11773

Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an attack against the underlying implementation of that function. The implementation of strtotime at the time the issue was discovered appeared to be resistant to a malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11772

Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Deutsche Bank Email Vulnerability Left Ex-Employees with Access πŸ•΄

Failures in computer and control systems are being blamed.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Series of Zero-Day Vulnerabilities Could Endanger 200 Million Devices πŸ•΄

Vulnerabilities in VxWorks' TCP stack could allow an attacker to execute random code, launch a DoS attack, or use the vulnerable system to attack other devices.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-18570

Planon before Live Build 41 has XSS.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Can We Stop Ransomware From Spreading? πŸ•΄

Here's how to stop them - or at least limit the systems it can reach.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Farewell, Dear Password? The Future of Identity and Authorization πŸ•΄

Many organizations, along with their tech teams, are questioning whether eliminating passwords as an authentication tool might augment their overall security posture.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Sextortion Email Scams Rise Sharply πŸ•΄

Cybercriminals are increasingly trying to trick people into paying ransoms by threatening to expose compromising activities to friends and family.

πŸ“– Read

via "Dark Reading: ".
πŸ” It's 2019, and one third of businesses still have active Windows XP deployments πŸ”

As end of support for the still-popular Windows 7 draws near, risks of unpatched operating systems are likely to be a significant security concern in the near future.

πŸ“– Read

via "Security on TechRepublic".
πŸ” 12 reasons why data breaches still happen πŸ”

Half of IT security leaders don't know if their cybersecurity tools are working, according to a report from the Ponemon Institute and AttackIQ.

πŸ“– Read

via "Security on TechRepublic".
❌ Former AWS Engineer Arrested as Capital One Admits Massive Data Breach ❌

More than 100 million customers have had their data compromised by a hacker after a cloud misconfiguration at Capital One.

πŸ“– Read

via "Threatpost".
πŸ•΄ Black Hat Q&A: Cracking Apple's T2 Security Chip πŸ•΄

Duo Labs' Mikhail Davidow and Jeremy Erickson speak about their research on the Apple T2 security chip, and why they're sharing it at Black Hat USA.

πŸ“– Read

via "Dark Reading: ".
⚠ Post-Equifax settlement, NY updates data breach notification laws ⚠

Equifax is fined $675 million, while New York data breach notification law now covers biometrics, passwords, and more.

πŸ“– Read

via "Naked Security".
⚠ US chases fraudulent bitcoin exchange BTC-e for $100m ⚠

Two years ago, the US government fined an international cybercriminal and his fraudulent bitcoin exchange over $100m. Now, it's going after them for the money.

πŸ“– Read

via "Naked Security".
⚠ Listening in: Humans hear the private info Siri accidentally records ⚠

Apple Watch and HomePod have the highest rate of inadvertent recordings, a whistleblower says.

πŸ“– Read

via "Naked Security".
⚠ Hackers target Telegram accounts through voicemail backdoor ⚠

As politicians should know by now, secure messaging apps such as Telegram can quickly become a double-edged sword.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2017-18380

edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9290

In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ CISOs Must Evolve to a Data-First Security Program πŸ•΄

Such a program will require effort and reprioritization, but it will let your company fight modern-day threats and protect your most important assets.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Suffering SOC Saga Continues πŸ•΄

New study exposes low confidence among security professionals in their security operations centers.

πŸ“– Read

via "Dark Reading: ".