InfoSec News 20191204

  • Publicado: Qua, 04/12/2019 - 10:41
f

Top News


  • A critical flaw in Jetpack exposes millions of WordPress

"Experts at Cisco Talos found two vulnerabilities in the GoAhead embedded web server, including a critical remote code execution flaw."

Link

TLP1 : Green

  • Code Execution Vulnerabilities Patched in Accusoft ImageGear

"Vulnerabilities in document and imaging library Accusoft ImageGear could allow attackers to execute code remotely on vulnerable machines, Cisco Talos has discovered.."

Link

TLP1 : Green

  • Mozilla has removed four extensions from Avast and AVG from the Firefox site that are suspected to track user activity online.

"Four Avast and AVG Firefox extensions have been removed from Mozilla Addons Site over concerns of spying of users."

Link

TLP1 : Green

Cybersecurity State: Surveillance, Cyberwarfare, Cybercriminality and Hacktivism


  • Cryptocurrency exchange locks its cold wallet as CEO “goes missing”

"Users of the Chinese cryptocurrency exchange IDAX must be feeling a little anxious right now.."

Link

TLP1 : Green

  • Avast and AVG Browser Extensions Spying On Chrome and Firefox Users

"If your Firefox or Chrome browser has any of the below-listed four extensions offered by Avast and its subsidiary AVG installed, you should disable or remove them as soon as possible."

Link

TLP1 : Green

  • FBI Issues Smart TV Cybersecurity Warning

"The Federal Bureau of Investigation has issued a warning to holiday shoppers who are planning to swap some of their hard-earned cash for a smart TV.."

Link

TLP1 : Green

Breaches: Data Breaches and Hacks


  • Canon Medical Unveils a Multi-Level Cybersecurity Solution

"The Healthcare industry has constantly been in the firing line of hackers for quite a few years now. The reason behind the following limelight is the worth this data carries on the darker side of the web.”"

Link

TLP1 : Green

Vulnerabilities: Vulnerability Advisories, Zero-Days,Patches and Exploits


  • "Countering CAN bus vulnerability”

"Physical security and cybersecurity are needed to protect avionics in modern small airplanes and helicopters.."

Link

TLP1 : Green

  • 5 Addressing the Cybersecurity Skills Shortage Through Upskilling and Retention

"For years, security leaders have been talking about the cybersecurity skills shortage.#34;

Link

TLP1 : Green

Incident Response: Infrastructure, Training, SIEM and Incident Handling


  • Tripwire Patch Priority Index for November 2019

"Tripwire’s November 2019 Patch Priority Index (PPI) brings together important vulnerabilities from Microsoft, Oracle, Linux Kernel and Adobe."

Link

TLP1 : Green

Technical Articles: Forensics, Reverse Engineering, Malware, Phishing, Pentesting, Software Security and Cryptography


  • Detecções de vírus caíram em 2019, de acordo com a Microsoft

"Estatísticas de segurança da empresa revelam que ataques de phishing e DDoS estão em alta, apesar da queda no surgimento de novas ameaças."

Link

TLP1 : Green

 

 

1Traffic Light Protocol (TLP) [1] for information sharing:

 

 

  • Red:Not for disclosure, restricted to participants only.
  • Amber: Limited disclosure, restricted to participants organizations.
  • Green: Limited disclosure, restricted to the community.

 


[1]https://www.first.org/tlp