πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-3341 β€Ό

A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5 through 20.x before 20.0.219.0, allows an attacker to read any file on the host file system via an HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26307 β€Ό

An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the processor does not support the CPUID instruction, which is unsound and causes a deterministic crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26306 β€Ό

An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() methods.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26304 β€Ό

PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26308 β€Ό

An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated memory, violating soundness.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26303 β€Ό

PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26305 β€Ό

An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violating soundness.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 2020 Marked a Renaissance in DDoS Attacks πŸ•΄

Amid the global pandemic, cybercriminals ramped up use of one of the oldest attack techniques around.

πŸ“– Read

via "Dark Reading".
❌ Lazarus Affiliate β€˜ZINC’ Blamed for Campaign Against Security Researcher ❌

New details emerge of how North Korean-linked APT won trust of experts and exploited Visual Studio to infect systems with β€˜Comebacker’ malware.

πŸ“– Read

via "Threat Post".
⚠ The mystery of the missing Perl website ⚠

A long-running domain supporting the popular programming language Perl has suddenly vanished. We don't yet know how or why.

πŸ“– Read

via "Naked Security".
πŸ” Digital Guardian Named a Top Place to Work in the US πŸ”

Digital Guardian was named a top place to work in the United States in 2021!

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Is the Web Supply Chain Next in Line for State-Sponsored Attacks? πŸ•΄

Attackers go after the weak links first, and the Web supply chain provides an abundance of weak links to target.

πŸ“– Read

via "Dark Reading".
πŸ” Friday Five 1/29 πŸ”

Linux bugs, hacker personas, and the Emotet botnet disrupted - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "Digital Guardian".
β€Ό CVE-2021-25909 β€Ό

ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause a denial of service condition on the device. An attacker could exploit this vulnerability by sending specific packets to the port 7919.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25910 β€Ό

Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25123 β€Ό

The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice addlicense_func function.

πŸ“– Read

via "National Vulnerability Database".
🦿 6 data categories to learn for faster cybersecurity responses 🦿

By knowing the different types of data, it can help your company protect itself from breaches and better recover from a cyberattack.

πŸ“– Read

via "Tech Republic".
πŸ” Friday Five 1/29 πŸ”

Linux bugs, hacker personas, and the Emotet botnet disrupted - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "Digital Guardian".
πŸ” Digital Guardian Named a Top Place to Work in the US πŸ”

Digital Guardian was named a top place to work in the United States in 2021!

πŸ“– Read

via "Digital Guardian".
🦿 Identifying data terms can improve cybersecurity efficiency 🦿

The term "data" is vague. Knowing the types of data helps companies protect themselves and better recover from a cyberattack.

πŸ“– Read

via "Tech Republic".
❌ Apple iOS 14 Thwarts iMessage Attacks With BlastDoor System ❌

Apple has made structural improvements in iOS 14 to block message-based, zero-click exploits.

πŸ“– Read

via "Threat Post".