πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Breach Data Highlights a Pivot to Orgs Over Individuals πŸ•΄

In 2020, breaches were down by 19%, while the impact of those compromises -- measured in people affected -- fell by nearly two-thirds.

πŸ“– Read

via "Dark Reading".
❌ LogoKit Simplifies Office 365, SharePoint β€˜Login’ Phishing Pages ❌

A phishing kit has been found running on at least 700 domains - and mimicking services via false SharePoint, OneDrive and Office 365 login portals.

πŸ“– Read

via "Threat Post".
❌ Utah Ponders Making Online β€˜Catfishing’ a Crime ❌

Pretending to be someone else online could become a criminal offense, setting a precedent for other states to follow.

πŸ“– Read

via "Threat Post".
⚠ Cybersecurity tips for university students ⚠

An informal survey of 15 students suggested that most were unconcerned about cybersecurity. Don't be one of them!

πŸ“– Read

via "Naked Security".
🦿 The top 5 reasons data privacy should be practiced every day 🦿

Working from home because of the pandemic has led to sensitive corporate information being stored on private devices, and experts say protecting data must become a business imperative.

πŸ“– Read

via "Tech Republic".
🦿 How to protect your organization's remote endpoints against ransomware 🦿

A lack of visibility into remote endpoints can leave your organization vulnerable to ransomware attacks, says security provider Illumio.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-22875 β€Ό

Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22874 β€Ό

Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.

πŸ“– Read

via "National Vulnerability Database".
🦿 Data Privacy Day: 10 experts give advice for protecting your business 🦿

Data Privacy Day is dedicated to achieving sound privacy practices to protect businesses and customers. Learn insights from 10 experts in the field to help safeguard your company.

πŸ“– Read

via "Tech Republic".
🦿 How to install and use ClamAV on Ubuntu Server 20.04 🦿

Your Linux servers could use a system to scan for malicious files. Jack Wallen shows you how with the help of ClamAV.

πŸ“– Read

via "Tech Republic".
❌ Rocke Group’s Malware Now Has Worm Capabilities ❌

The Pro-Ocean cryptojacking malware now comes with the ability to spread like a worm, as well as harboring new detection-evasion tactics.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-1723 β€Ό

The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks. Versions shipped with Red Hat Mobile Aplication Platform 4 are believed to be vulnerable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20183 β€Ό

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20187 β€Ό

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-25016 β€Ό

There is an unsafe incomplete reset of PATH in OpenDoas 6.6 through 6.8 when changing the user context.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3160 β€Ό

Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26272 β€Ό

The Electron framework lets you write cross-platform desktop applications using JavaScript, HTML and CSS. In affected versions of Electron IPC messages sent from the main process to a subframe in the renderer process, through webContents.sendToFrame, event.reply or when using the remote module, can in some cases be delivered to the wrong frame. If your app uses remote, calls webContents.sendToFrame, or calls event.reply in an IPC message handler then it is impacted by this issue. This has been fixed in versions 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9. There are no workarounds for this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35517 β€Ό

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36115 β€Ό

Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25647 β€Ό

Mobile application "Testes de Codigo" v11.3 and prior allows stored XSS by injecting a payload in the "feedback" message field causing it to be stored in the remote database and leading to its execution on client devices when loading the "feedback list", either by accessing the website directly or using the mobile application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20184 β€Ό

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

πŸ“– Read

via "National Vulnerability Database".