πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-25763 β€Ό

In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25761 β€Ό

In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25208 β€Ό

In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28653 β€Ό

Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2506 β€Ό

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to obtain control of a QNAP device. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ SolarWinds Attackers Spent Months in Corporate Email System: Report πŸ•΄

SolarWinds' CEO says evidence indicates attackers lurked in the company's Office 365 email system for months ahead of the attack.

πŸ“– Read

via "Dark Reading".
πŸ•΄ An Observability Pipeline Could Save Your SecOps Team πŸ•΄

Traditional monitoring approaches are proving brittle as security operations teams need better visibility into dynamic environments.

πŸ“– Read

via "Dark Reading".
🦿 Account takeover attacks spiked in 2020, Kaspersky says 🦿

The surge gives further credence to the idea that cybercrime is less about tech know-how and more about social engineering, according to its fraud report.

πŸ“– Read

via "Tech Republic".
🦿 How a global law enforcement effort took down the Emotet botnet 🦿

A joint effort across the US and Europe led to the disruption of Emotet and the arrest of two gang members, says Digital Shadows.

πŸ“– Read

via "Tech Republic".
πŸ” How to Protect Data and Defend Against State-Sponsored Hackers πŸ”

NIST has released new tools for defenders to protect sensitive information and mitigate state-sponsored hackers.

πŸ“– Read

via "Digital Guardian".
❌ New Malware Hijacks Kubernetes Clusters to Mine Monero ❌

Researchers warn that the Hildegard malware is part of 'one of the most complicated attacks targeting Kubernetes.'

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-9388 β€Ό

CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-9390 β€Ό

SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-9389 β€Ό

A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Patch Imperfect: Software Fixes Failing to Shut Out Attackers πŸ•΄

Incomplete patches are allowing attackers to continue exploiting the same vulnerabilities, reducing the cost to compromise.

πŸ“– Read

via "Dark Reading".
❌ Emotet’s Takedown: Have We Seen the Last of the Malware? ❌

A week after law enforcement agencies said they took down Emotet, there has been no sign of the prolific malware.

πŸ“– Read

via "Threat Post".
❌ Second SolarWinds Attack Group Breaks into USDA Payroll β€” Report ❌

A second APT, potentially linked to the Chinese government, could be behind the Supernova malware.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-26023 β€Ό

The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26024 β€Ό

The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Concerns Over API Security Grow as Attacks Increase πŸ•΄

Some 66% of organizations say they have slowed deploying an app into production because of API security concerns.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-26689 β€Ό

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021).

πŸ“– Read

via "National Vulnerability Database".