Author: DEFENDEDGE
-
Vulnerability Summary for the Week of November 16, 2020
Original release date: November 23, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet have assigned CVSS scores. Please visit NVD for updated vulnerability entries, which include CVSS scores once they are available. High Vulnerabilities Primary Vendor… Read more
-
Manchester United: IT Systems Disrupted in Cyberattack
The popular U.K. soccer club confirmed an attack but said personal fan data remains secure. Read more
-
VMware Fixes Critical Flaw in ESXi Hypervisor
The critical and important-severity flaws were found by a team at the China-based Tiunfu Cup hacking challenge. Read more
-
Facebook Messenger Bug Allows Spying on Android Users
The company patched a vulnerability that could connected video and audio calls without the knowledge of the person receiving them. Read more
-
German COVID-19 Contact-Tracing Vulnerability Allowed RCE
Bug hunters at GitHub Security Labs help shore up German contact tracing app security, crediting open source collaboration. Read more
-
GO SMS Pro Android App Exposes Private Photos, Videos and Messages
The vulnerable version of the app, which has 100 million users, uses easily predictable URLs to link to private content. Read more
-
IoT Cybersecurity Improvement Act Passed, Heads to President’s Desk
Security experts praised the newly approved IoT law as a step in the right direction for insecure connected federal devices. Read more
-
VMware Releases Security Updates for VMware SD-WAN Orchestrator
Original release date: November 19, 2020<br/><p>VMware has released security updates to address multiple vulnerabilities in VMware SD-WAN Orchestrator. An attacker could exploit some of these vulnerabilities to take control of an affected system.</p> <p>The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review VMware Security Advisory <a href=”https://www.vmware.com/security/advisories/VMSA-2020-0025.html”>VMSA-2020-0025</a> and apply the necessary… Read more
-
Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird
Original release date: November 19, 2020<br/><p>Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, and Thunderbird. An attacker could exploit some of these vulnerabilities to take control of an affected system.</p> <p>The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Mozilla Security Advisories for <a href=”https://www.mozilla.org/en-US/security/advisories/mfsa2020-50″>Firefox 83</a>,… Read more
-
Google Releases Security Updates for Chrome
Original release date: November 19, 2020<br/><p>Google has released Chrome version 87.0.4280.66 for Windows, Mac, and Linux to address multiple vulnerabilities. Some of these vulnerabilities could allow an attacker to take control of an affected system.</p> <p>The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the <a href=”https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_17.html”>Chrome Release</a> and apply the… Read more