πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Lazarus Affiliate β€˜ZINC’ Blamed for Campaign Against Security Researcher ❌

New details emerge of how North Korean-linked APT won trust of experts and exploited Visual Studio to infect systems with β€˜Comebacker’ malware.

πŸ“– Read

via "Threat Post".
⚠ The mystery of the missing Perl website ⚠

A long-running domain supporting the popular programming language Perl has suddenly vanished. We don't yet know how or why.

πŸ“– Read

via "Naked Security".
πŸ” Digital Guardian Named a Top Place to Work in the US πŸ”

Digital Guardian was named a top place to work in the United States in 2021!

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Is the Web Supply Chain Next in Line for State-Sponsored Attacks? πŸ•΄

Attackers go after the weak links first, and the Web supply chain provides an abundance of weak links to target.

πŸ“– Read

via "Dark Reading".
πŸ” Friday Five 1/29 πŸ”

Linux bugs, hacker personas, and the Emotet botnet disrupted - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "Digital Guardian".
β€Ό CVE-2021-25909 β€Ό

ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause a denial of service condition on the device. An attacker could exploit this vulnerability by sending specific packets to the port 7919.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25910 β€Ό

Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25123 β€Ό

The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice addlicense_func function.

πŸ“– Read

via "National Vulnerability Database".
🦿 6 data categories to learn for faster cybersecurity responses 🦿

By knowing the different types of data, it can help your company protect itself from breaches and better recover from a cyberattack.

πŸ“– Read

via "Tech Republic".
πŸ” Friday Five 1/29 πŸ”

Linux bugs, hacker personas, and the Emotet botnet disrupted - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "Digital Guardian".
πŸ” Digital Guardian Named a Top Place to Work in the US πŸ”

Digital Guardian was named a top place to work in the United States in 2021!

πŸ“– Read

via "Digital Guardian".
🦿 Identifying data terms can improve cybersecurity efficiency 🦿

The term "data" is vague. Knowing the types of data helps companies protect themselves and better recover from a cyberattack.

πŸ“– Read

via "Tech Republic".
❌ Apple iOS 14 Thwarts iMessage Attacks With BlastDoor System ❌

Apple has made structural improvements in iOS 14 to block message-based, zero-click exploits.

πŸ“– Read

via "Threat Post".
🦿 CISA warns of attacks on cloud-based services 🦿

Companies are most vulnerable when employees work from home or use a combination of company and personal devices.

πŸ“– Read

via "Tech Republic".
🦿 SolarWinds attack: Cybersecurity experts share lessons learned and how to protect your business 🦿

The highly sophisticated SolarWinds attack was designed to circumvent threat detectionβ€”and it did, for much too long. Two cybersecurity experts share some valuable lessons learned from the attack.

πŸ“– Read

via "Tech Republic".
🦿 Is your boss spying on you? It's possible, and privacy laws aren't there yet 🦿

Some companies are using monitoring software to keep tabs on employees working from home. Some organizations are crying foul.

πŸ“– Read

via "Tech Republic".
🦿 Vishing: FBI says beware of voice phishing at large organizations 🦿

Attackers are tricking employees into logging into phishing sites.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-3345 β€Ό

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt before 1.9.1 has a heap-based buffer overflow when the digest final function sets a large count value.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20586 β€Ό

Resource management errors vulnerability in a robot controller of MELFA FR Series(controller "CR800-*V*D" of RV-*FR***-D-* all versions, controller "CR800-*HD" of RH-*FRH***-D-* all versions, controller "CR800-*HRD" of RH-*FRHR***-D-* all versions, controller "CR800-*V*R with R16RTCPU" of RV-*FR***-R-* all versions, controller "CR800-*HR with R16RTCPU" of RH-*FRH***-R-* all versions, controller "CR800-*HRR with R16RTCPU" of RH-*FRHR***-R-* all versions, controller "CR800-*V*Q with Q172DSRCPU" of RV-*FR***-Q-* all versions, controller "CR800-*HQ with Q172DSRCPU" of RH-*FRH***-Q-* all versions, controller "CR800-*HRQ with Q172DSRCPU" of RH-*FRHR***-Q-* all versions) and a robot controller of MELFA CR Series(controller "CR800-CVD" of RV-8CRL-D-* all versions, controller "CR800-CHD" of RH-*CRH**-D-* all versions) as well as a cooperative robot ASSISTA(controller "CR800-05VD" of RV-5AS-D-* all versions) allows a remote unauthenticated attacker to cause a DoS of the execution of the robot program and the Ethernet communication by sending a large amount of packets in burst over a short period of time. As a result of DoS, an error may occur. A reset is required to recover it if the error occurs.

πŸ“– Read

via "National Vulnerability Database".
❌ Industrial Gear at Risk from Fuji Code-Execution Bugs ❌

Fuji Electric’s Tellus Lite V-Simulator and V-Server Lite can allow attackers to take advantage of operational technology (OT)-IT convergence on factory floors, at utility plants and more.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-3346 β€Ό

Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.

πŸ“– Read

via "National Vulnerability Database".