πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 10 Tips for Building Compliance by Design into Cloud Architecture πŸ•΄

A pair of experts pass along lessons learned while building out the team and processes necessary to support Starbucks' mobile app.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Disclosure Does Little to Dissuade Cyber Spies πŸ•΄

In the past, outing nation-state cyber espionage groups caused a few to close up shop, but nowadays actors are more likely to switch to new infrastructure and continue operations.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ The Edge Cartoon Contest: Need a Lift? πŸ•΄

Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Google Launches OpenTitan Project to Open Source Chip Security πŸ•΄

OpenTitan is an open source collaboration among Google and technology companies to strengthen root-of-trust chip design.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2010-2222

The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-2064 (rpcbind)

rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-2061 (rpcbind)

rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2005-2354

Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ CrowdStrike Adds New Products & Web Store Apps πŸ•΄

Company introduces Falcon for AWS, Falcon Firewall Management, and third-party applications.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Siemens PLC Feature Can Be Exploited for Evil - and for Good πŸ•΄

A hidden feature in some newer models of the vendor's programmable logic controllers leaves the devices open to attack. Siemens says it plans to fix it.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2007-2841

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-3947. Reason: This candidate is a reservation duplicate of CVE-2007-3947. Notes: All CVE users should reference CVE-2007-3947 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2007-0899

There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2006-4245

archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2006-4243

linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2006-3100

termpkg 3.3 suffers from buffer overflow.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2006-0062

xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2006-0061

xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.

πŸ“– Read

via "National Vulnerability Database".
⚠ Founders of β€˜worthless cryptocurrency’ ATM Coin fined over $4.25m scam ⚠

Invest in "binary options," they said, neglecting to mention the software set up to rig transactions so that customers lost the gamble.

πŸ“– Read

via "Naked Security".
⚠ Ransomware attacks in Spain leave radio station in β€œhysteria” ⚠

A ransomware attack has ransacked at least two Spanish companies, leaving their employees without computer access.

πŸ“– Read

via "Naked Security".