πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ›  Sifter 11.5 πŸ› 

Sifter is a osint, recon, and vulnerability scanner. It combines a plethora of tools within different module sets in order to quickly perform recon tasks, check network firewalling, enumerate remote and local hosts, and scan for the blue vulnerabilities within Microsoft systems and if unpatched, exploits them.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Digital Identity Is the New Security Control Plane πŸ•΄

Simplifying the management of security systems helps provide consistent protection for the new normal.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Building Your Personal Privacy Risk Tolerance Profile πŸ•΄

Even today, on Data Privacy Day, privacy professionals give you permission to admit you actually love targeted ads.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-4682 β€Ό

IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4888 β€Ό

IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 190912.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13569 β€Ό

A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the victim. An attacker can send an HTTP request to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Data Privacy Day 2021: Seven Tips to Keep Your Data Safe πŸ”

We’re sharing seven tips to help you keep your data safe this Data Privacy Day.

πŸ“– Read

via "Digital Guardian".
❌ Mimecast Confirms SolarWinds Hack as List of Security Vendor Victims Snowball ❌

A growing number of cybersecurity vendors like CrowdStrike, Fidelis, FireEye, Malwarebytes, Palo Alto Networks and Qualys are confirming being targeted in the espionage attack.

πŸ“– Read

via "Threat Post".
πŸ•΄ Breach Data Highlights a Pivot to Orgs Over Individuals πŸ•΄

In 2020, breaches were down by 19%, while the impact of those compromises -- measured in people affected -- fell by nearly two-thirds.

πŸ“– Read

via "Dark Reading".
❌ LogoKit Simplifies Office 365, SharePoint β€˜Login’ Phishing Pages ❌

A phishing kit has been found running on at least 700 domains - and mimicking services via false SharePoint, OneDrive and Office 365 login portals.

πŸ“– Read

via "Threat Post".
❌ Utah Ponders Making Online β€˜Catfishing’ a Crime ❌

Pretending to be someone else online could become a criminal offense, setting a precedent for other states to follow.

πŸ“– Read

via "Threat Post".
⚠ Cybersecurity tips for university students ⚠

An informal survey of 15 students suggested that most were unconcerned about cybersecurity. Don't be one of them!

πŸ“– Read

via "Naked Security".
🦿 The top 5 reasons data privacy should be practiced every day 🦿

Working from home because of the pandemic has led to sensitive corporate information being stored on private devices, and experts say protecting data must become a business imperative.

πŸ“– Read

via "Tech Republic".
🦿 How to protect your organization's remote endpoints against ransomware 🦿

A lack of visibility into remote endpoints can leave your organization vulnerable to ransomware attacks, says security provider Illumio.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-22875 β€Ό

Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22874 β€Ό

Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.

πŸ“– Read

via "National Vulnerability Database".
🦿 Data Privacy Day: 10 experts give advice for protecting your business 🦿

Data Privacy Day is dedicated to achieving sound privacy practices to protect businesses and customers. Learn insights from 10 experts in the field to help safeguard your company.

πŸ“– Read

via "Tech Republic".
🦿 How to install and use ClamAV on Ubuntu Server 20.04 🦿

Your Linux servers could use a system to scan for malicious files. Jack Wallen shows you how with the help of ClamAV.

πŸ“– Read

via "Tech Republic".
❌ Rocke Group’s Malware Now Has Worm Capabilities ❌

The Pro-Ocean cryptojacking malware now comes with the ability to spread like a worm, as well as harboring new detection-evasion tactics.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-1723 β€Ό

The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks. Versions shipped with Red Hat Mobile Aplication Platform 4 are believed to be vulnerable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20183 β€Ό

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

πŸ“– Read

via "National Vulnerability Database".