πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Critical Cisco β€˜CDPwn’ Flaws Break Network Segmentation ❌

Cisco has released patches to address the five vulnerabilities, which could lead to remote code-execution and denial of service.

πŸ“– Read

via "Threatpost".
❌ Critical Cisco β€˜CDPwn’ Protocol Flaws Explained: Podcast ❌

The researcher behind the five critical Cisco flaws, collectively called CDPwn, talks about why Layer 2 protocols are under-researched when it comes to security vulnerabilities.

πŸ“– Read

via "Threatpost".
❌ WhatsApp Bug Allows Malicious Code-Injection, One-Click RCE ❌

A high-severity vulnerability could allow cybercriminals to push malware or remotely execute code, using seemingly innocuous messages.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2013-0507

IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability

πŸ“– Read

via "National Vulnerability Database".
⚠ PayPal SMS scams – don’t fall for them! ⚠

Text messages may be old hat - but SMS is still a handy tool for crooks out to find more about you.

πŸ“– Read

via "Naked Security".
⚠ Coronavirus β€œsafety measures” email is a phishing scam ⚠

Sadly, cybercrooks love a crisis, because it gives them a believable reason to contact you with a phishing scam. Take care out there!

πŸ“– Read

via "Naked Security".
❌ New Lemon Duck Malware Campaign Targets IoT, Large Manufacturers ❌

Malware campaign targets global manufacturers that are still dependent on Windows 7 subsystems to run fleets of IoT endpoints.

πŸ“– Read

via "Threatpost".
πŸ•΄ Keeping Compliance Data-Centric Amid Accelerating Regulation πŸ•΄

As the regulatory landscape transforms, it's still smart to stay strategically focused on protecting your data.

πŸ“– Read

via "Dark Reading: ".
πŸ›  ISO-8385 Protocol Fuzzer πŸ› 

This python script is a fuzzer for the ISO-8385 financial protocol. It is compatible with sulley and bofuzz and is now part of the official bofuzz release.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  nfstream 3.1.2 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  Clam AntiVirus Toolkit 0.102.2 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ” SEC Issues Cybersecurity and Resiliency Best Practices πŸ”

Data loss prevention is one of eight key practices outlined by the SEC last week to enhance cybersecurity preparedness and operational resiliency.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Tips on keeping a Google Photos-type video bug from impacting cloud-based files πŸ”

The private videos of some Google Photos users were accidentally shared with other people. Here's how to secure online files to protect them from exposure.

πŸ“– Read

via "Security on TechRepublic".
❌ CamuBot Banking Trojan Returns In Targeted Attacks ❌

The malware is back in targeted attacks against Brazilian banking customers, this time using a new technique that involves mobile app authorization.

πŸ“– Read

via "Threatpost".
πŸ•΄ What is a Privileged Access Workstation (PAW)? πŸ•΄

Ask the Experts -- about a technological game of keep-away that protects the most precious resources from the greatest dangers.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Emotet Preps for Tax Season with New Phishing Campaign πŸ•΄

Malicious emails in a new attack campaign contain links and attachments claiming to lead victims to W-9 forms.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-0220

Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5304

A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-4815

Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-4662

PmWiki before 2.2.21 has XSS.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ IoT Malware Campaign Infects Global Manufacturing Sites πŸ•΄

The infection uses Lemon_Duck PowerShell malware variant to exploit vulnerabilities in embedded devices at manufacturing sites.

πŸ“– Read

via "Dark Reading: ".