πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-25229 β€Ό

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the database server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0346 β€Ό

In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05371580.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25248 β€Ό

An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25246 β€Ό

An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0348 β€Ό

In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05349201.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25245 β€Ό

An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of settings informaiton.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25243 β€Ό

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25236 β€Ό

A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25239 β€Ό

An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0345 β€Ό

In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05432974.

πŸ“– Read

via "National Vulnerability Database".
❌ Android Devices Prone to Botnet’s DDoS Onslaught ❌

A new DDoS botnet propagates via the Android Debug Bridge and uses Tor to hide its activity.

πŸ“– Read

via "Threat Post".
πŸ•΄ Microsoft Says It's Time to Attack Your Machine-Learning Models πŸ•΄

With access to some training data, Microsoft's red team recreated a machine-learning system and found sequences of requests that resulted in a denial-of-service.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Web Application Attacks Grow Reliant on Automated Tools πŸ•΄

Attackers often use automation in fuzzing attacks, injection attacks, fake bots, and application DDoS attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ IBM Offers $3M in Grants to Defend Schools from Cyberattacks πŸ•΄

The grants will be awarded to six school districts in the United States to help prepare for, and respond to, cyberattacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google's Payout to Bug Hunters Hits New High πŸ•΄

Over 660 researchers from 62 countries collected rewards for reporting bugs in Chrome, Android, and other Google technologies.

πŸ“– Read

via "Dark Reading".
⚠ Chrome zero-day browser bug found β€“ patch now! ⚠

Google is playing its cards close to its chest to avoid giving too much away.

πŸ“– Read

via "Naked Security".
πŸ•΄ AI and APIs: The A+ Answers to Keeping Data Secure and Private πŸ•΄

Many IT and security leaders view regulations and internal processes designed to manage and secure data as additional red tape, slowing processes and innovation. Nothing could be further from the truth.

πŸ“– Read

via "Dark Reading".
πŸ” Friday Five 2/5 πŸ”

Chrome updates, open source frameworks, and an interview with a cybercriminal - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Cybercrime Goes Mainstream πŸ•΄

Organized cybercrime is global in scale and the second-greatest risk over the next decade.

πŸ“– Read

via "Dark Reading".
❌ Ransomware Attacks Hit Major Utilities ❌

Electrobras, the largest power company in Latin America, faced a temporary suspension of some operations.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-26711 β€Ό

A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/default.htm turl parameter.

πŸ“– Read

via "National Vulnerability Database".