πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” What is NIST CSF? πŸ”

The National Institute of Standards and Technology's Cybersecurity Framework is designed to help organizations manage their security risk; in this blog we'll go over its requirements, penalties for failing to comply with it, and best practices.

πŸ“– Read

via "Digital Guardian".
🦿 How to combat future cyberattacks following the SolarWinds breach 🦿

How can and should governments respond to and better protect themselves from serious cyberattacks from hostile nations?

πŸ“– Read

via "Tech Republic".
πŸ•΄ Security as Code: How Repeatable Policy-Driven Deployment Improves Security πŸ•΄

The SaC approach lets users codify and enforce a secure state of application configuration deployment that limits risk.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-28460 β€Ό

This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28448 β€Ό

This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.

πŸ“– Read

via "National Vulnerability Database".
❌ Joker’s Stash Carding Site Taken Down, for Now ❌

The underground payment-card data broker saw its blockchain DNS sites taken offline after an apparent law-enforcement effort.

πŸ“– Read

via "Threat Post".
❌ Tech Giants Lend WhatsApp Support in Spyware Case Against NSO Group ❌

Google, Microsoft, Cisco Systems and others want appeals court to deny immunity to Israeli company for its alleged distribution of spyware and illegal cyber-surveillance activities.

πŸ“– Read

via "Threat Post".
πŸ•΄ Law Enforcement Disrupts VPN Services Enabling Cybercrime πŸ•΄

The United States and international partners shut down three bulletproof hosting services used to facilitate criminal activity.

πŸ“– Read

via "Dark Reading".
πŸ›  Sifter 11.2 πŸ› 

Sifter is a osint, recon, and vulnerability scanner. It combines a plethora of tools within different module sets in order to quickly perform recon tasks, check network firewalling, enumerate remote and local hosts, and scan for the blue vulnerabilities within Microsoft systems and if unpatched, exploits them.

πŸ“– Read

via "Packet Storm Security".
⚠ Does a friend β€œneed money urgently”? Check your facts before paying out… ⚠

Don't get scammed by fake online requests to help a friend online. Check your facts first - here's why.

πŸ“– Read

via "Naked Security".
🦿 UK lawmakers propose law banning retail bots after PS5 fiasco 🦿

The legislation would both ban the resale of goods acquired using bots and the resale of tech products above the manufacturers' price.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2019-11782 β€Ό

Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-15645 β€Ό

Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-15633 β€Ό

Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-11784 β€Ό

Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party to.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-15641 β€Ό

Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25106 β€Ό

Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and then upload a Trojan horse with the Supremo.exe filename.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-11785 β€Ό

Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-11783 β€Ό

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13570 β€Ό

A use-after-free vulnerability exists in the JavaScript engine of Foxit SoftwareÒ€ℒs PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger the reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-11781 β€Ό

Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".