πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Ransomware can be installed via ghost accounts 🦿

Active accounts for people who have left your organization can make exploitation easy, according to Sophos.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Iranian Cyber Groups Spying on Dissidents & Others of Interest to Government πŸ•΄

A new investigation of two known threat groups show cyber actors are spying on mobile devices and PCs belonging to targeted users around the world.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Fighting Fileless Malware, Part 2: Countermeasures πŸ•΄

Why do fileless attacks persist? Let's break down the strengths and weaknesses of the existing mitigations.

πŸ“– Read

via "Dark Reading".
πŸ•΄ SolarWinds Attack Reinforces Importance of Principle of Least Privilege πŸ•΄

Taking stock of least-privilege policies will go a long way toward hardening an organization's overall security posture.

πŸ“– Read

via "Dark Reading".
❌ Cyberpunk 2077 Publisher Hit with Hack, Threats and Ransomware ❌

CD Projekt Red was hit with a cyberattack, and the attackers are threatening to release source code for Witcher 3, corporate documents and more.

πŸ“– Read

via "Threat Post".
❌ Android Devices Hunted by LodaRAT Windows Malware ❌

The LodaRAT - known for targeting Windows devices - has been discovered also targeting Android devices in a new espionage campaign.

πŸ“– Read

via "Threat Post".
⚠ Beware of technical β€œexperts” bombarding you with bug reports ⚠

Beware pseudo-geeks bearing 'gifts'.

πŸ“– Read

via "Naked Security".
🦿 FBI, Secret Service investigating cyberattack on Florida water treatment plant 🦿

Local officials said someone took over their TeamViewer system and dangerously increased the levels of lye in the town's water.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-21146 β€Ό

Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27259 β€Ό

The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4795 β€Ό

IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information to an unauthorized user using a specially crafted HTTP request. IBM X-Force ID: 189446.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27261 β€Ό

The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21147 β€Ό

Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26676 β€Ό

gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3394 β€Ό

Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious user for a local privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27257 β€Ό

This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21142 β€Ό

Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21148 β€Ό

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4791 β€Ό

IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due to improper certificate validation. IBM X-Force ID: 189379.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4995 β€Ό

IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session. IBM X-Force ID: 192912.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21144 β€Ό

Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

πŸ“– Read

via "National Vulnerability Database".