πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 'Cuba' Ransomware Group Uses Every Trick in the Book πŸ•΄

How a Russian cybercrime group using Cuban Revolution references and iconography has emerged as one of the most profitable ransomware operations.

πŸ“– Read

via "Dark Reading".
πŸ‘2
πŸ•΄ The Physical Impact of Cyberattacks on Cities πŸ•΄

Understanding potential threats and regularly updating response plans are the best lines of defense in the new world of cyberattacks.

πŸ“– Read

via "Dark Reading".
🦿 VMware Explore 2023: Keynote Highlights 🦿

Explore enterprise applications and infrastructure, AI, tools for the remote workforce, machine learning, and more from VMware Explore 2023.

πŸ“– Read

via "Tech Republic".
🦿 VMware Explore 2023: Keynote Highlights 🦿

Explore enterprise applications and infrastructure, AI, tools for the remote workforce, machine learning, and more from VMware Explore 2023.

πŸ“– Read

via "Tech Republic".
πŸ•΄ When Leadership Style Is a Security Risk πŸ•΄

Risk-aware leaders can be a cybersecurity advantage. Their flexible leadership style and emphasis on security first help set the tone and demonstrate a commitment to avoiding risk.

πŸ“– Read

via "Dark Reading".
πŸ‘1
⚠ β€œSnakes in airplane mode” – what if your phone says it’s offline but isn’t? ⚠

WYSIWYG is short for "what you see is what you get". Except when it isn't...

πŸ“– Read

via "Naked Security".
πŸ•΄ Software Makers May Face Greater Liability in Wake of MOVEit Lawsuit πŸ•΄

Makers of vulnerable apps that are exploited in wide-scale supply chain attacks need to improve software security or face steep fines and settlement fees.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Tourists Give Themselves Away by Looking Up. So Do Most Network Intruders. β™ŸοΈ

In large metropolitan areas, tourists are often easy to spot because they're far more inclined than locals to gaze upward at the surrounding skyscrapers. Security experts say this same tourist dynamic is a dead giveaway in virtually all computer intrusions that lead to devastating attacks like ransomware, and that more organizations should set simple virtual tripwires that sound the alarm when authorized users and devices are spotted exhibiting this behavior.

πŸ“– Read

via "Krebs on Security".
⚠ Smart light bulbs could give away your password secrets ⚠

Cryptography isn't just about secrecy. You need to take care of authenticity (no imposters!) and integrity (no tampering!) as well.

πŸ“– Read

via "Naked Security".
🦿 VMware Explore 2023: Keynote Highlights 🦿

Explore enterprise applications and infrastructure, AI, tools for the remote workforce, machine learning, and more from VMware Explore 2023.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Newer, Better XLoader Signals a Dangerous Shift in macOS Malware πŸ•΄

Malware aimed at macOS is no longer just a knockoff of a Windows bug, as a new infostealer proliferating on Mac laptops demonstrates.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-48570 β€Ό

Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. NOTE: this issue exists because the CVE-2019-14318 fix was intentionally removed for functionality reasons.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19187 β€Ό

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23804 β€Ό

Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21426 β€Ό

Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21890 β€Ό

Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21723 β€Ό

A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remote attackers to cause a denial of service (crash) via opening of crafted ogg file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18839 β€Ό

Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46312 β€Ό

An issue was discovered IW44EncodeCodec.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37431 β€Ό

Multiple vulnerabilities in the web-based managementΓ‚ interface of EdgeConnect SD-WAN Orchestrator could allowΓ‚ an authenticated remote attacker to conduct SQL injectionΓ‚ attacks against the EdgeConnect SD-WAN OrchestratorΓ‚ instance. An attacker could exploit these vulnerabilities toΓ‚  Γ‚  obtain and modify sensitive information in the underlyingΓ‚ database potentially leading to the exposure and corruptionΓ‚ of sensitive data controlled by the EdgeConnect SD-WANΓ‚ Orchestrator host.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19185 β€Ό

Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

πŸ“– Read

via "National Vulnerability Database".