πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-10561

Improper initialization of local variables which are parameters to sfs api may cause invalid pointer dereference and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, MDM9206, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QM215, SDA660, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10558

While transferring data from APPS to DSP, Out of bound in FastRPC HLOS Driver due to the data buffer which can be controlled by DSP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SDX55, SM6150, SM8150, SM8250, SXR1130, SXR2130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10548

While trying to obtain datad ipc handle during DPL initialization, Heap use-after-free issue can occur if modem SSR occurs at same time in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCS605, QM215, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SXR1130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10532

Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, Nicobar, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM8150, SM8250, SXR1130, SXR2130

πŸ“– Read

via "National Vulnerability Database".
⚠ China and US top user data requests in Apple transparency report ⚠

Most of the US and China's requests had to do with investigations into fraud, suspected account access and phishing.

πŸ“– Read

via "Naked Security".
πŸ•΄ 7 Tips for Infosec Pros Considering A Lateral Career Move πŸ•΄

Looking to switch things up but not sure how to do it? Security experts share their advice for switching career paths in the industry.

πŸ“– Read

via "Dark Reading: ".
⚠ Citrix ships patches as vulnerable servers come under attack ⚠

Citrix has issued its first set of patches fixing a nasty vulnerability that's been hanging over some of its biggest products.

πŸ“– Read

via "Naked Security".
❌ Hacker Leaks More Than 500K Telnet Credentials for IoT Devices ❌

Bad actor obtained passwords for servers, home routers, and smart devices by scanning internet for devices open to the Telnet port.

πŸ“– Read

via "Threatpost".
πŸ•΄ Elaborate Honeypot 'Factory' Network Hit with Ransomware, RAT, and Cryptojacking πŸ•΄

A fictitious industrial company with phony employees personas, website, and PLCs sitting on a simulated factory network fooled malicious hackers - and raised alarms for at least one white-hat researcher who stumbled upon it.

πŸ“– Read

via "Dark Reading: ".
πŸ” If you don't like your browser, why won't you change to a different one? πŸ”

Commentary: Users tend to stick with their preferred browser even when it works poorly for them.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to use a physical security key to sign into supported websites πŸ”

A security key is a good option to use for two-factor authentication when logging into certain websites.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Windows 7 remains an albatross at many large organizations πŸ”

Among 60,000 large companies analyzed by security ratings company BitSight, almost 90% still have Windows 7 PCs in their environment.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Data Awareness Is Key to Data Security πŸ•΄

Traditional data-leak prevention is not enough for businesses facing today's dynamic threat landscape.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft Zero-Day Actively Exploited, Patch Forthcoming ❌

CVE-2020-0674 is a critical flaw for most Internet Explorer versions, allowing remote code execution and complete takeover.

πŸ“– Read

via "Threatpost".
❌ FTCODE Ransomware Now Steals Chrome, Firefox Credentials ❌

New versions of the ransomware now sniff out saved credentials for Internet Explorer, Mozilla Firefox, Mozilla Thunderbird, Google Chrome and Microsoft Outlook.

πŸ“– Read

via "Threatpost".
πŸ•΄ The Y2K Boomerang: InfoSec Lessons Learned from a New Date-Fix Problem πŸ•΄

We all make assumptions. They rarely turn out well. A new/old date problem offers a lesson in why that's so.

πŸ“– Read

via "Dark Reading: ".
πŸ” iOS-based devices: Zero-touch management essentials πŸ”

Managing multiple devices can be a full-time job. With a few tools in your arsenal, you can optimize mobile devices for zero-touch management.

πŸ“– Read

via "Security on TechRepublic".
❌ Citrix Accelerates Patch Rollout For Critical RCE Flaw ❌

Citrix has issued the first of several updates fixing a critical vulnerability in various versions of its Citrix Application Delivery Controller (ADC) and Citrix Gateway products.

πŸ“– Read

via "Threatpost".
πŸ•΄ Nearly 75% of SD-WAN Owners Lack Confidence Post-Digital Transformation πŸ•΄

More businesses think SD-WAN will reduce WAN costs, but only 37% think SD-WANs will help defend against malware and other threats.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Ransomware Upgrades with Credential-Stealing Tricks πŸ•΄

The latest version of the FTCode ransomware can steal credentials from five popular browsers and email clients.

πŸ“– Read

via "Dark Reading: ".