πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Linux 101: How to block users from setting up their own cron jobs 🦿

Jack Wallen shows you how to gain a bit more security on your Linux servers by blocking users from adding cron jobs.

πŸ“– Read

via "Tech Republic".
🦿 Forrester report highlights Zero Trust Edge model for networking and security infrastructure 🦿

According to Forrester, ZTE will be most helpful with securing and enabling remote workers while removing the difficult user VPNs.

πŸ“– Read

via "Tech Republic".
⚠ The massive coronavirus pandemic IT blunder with a funny side ⚠

He was either the smallest person who has ever lived, by an order of magnitude, or the heaviest person ever known, by two of them.

πŸ“– Read

via "Naked Security".
🦿 IRS issues urgent notice on scams aimed at tax professionals 🦿

Scammers are impersonating the IRS with emails carrying the subject line "Verifying your EFIN before e-filing."

πŸ“– Read

via "Tech Republic".
🦿 Linux 101: How to block users from setting up their own cron jobs 🦿

Jack Wallen shows you how to gain a bit more security on your Linux servers by blocking users from adding cron jobs.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-22701 β€Ό

A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when using the HTTP web interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22702 β€Ό

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts Telnet network traffic between a user and the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-12374 β€Ό

Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22703 β€Ό

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic between a user and the device.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Attackers Already Targeting Apple's M1 Chip with Custom Malware πŸ•΄

A proof-of-concept program infects systems with ARM64-compiled binaries and then reaches out to download additional functionality.

πŸ“– Read

via "Dark Reading".
🦿 How to find details about user logins on Linux 🦿

If you need to gather information on user logins for your Linux servers, Jack Wallen has just the tool for you.

πŸ“– Read

via "Tech Republic".
🦿 New malformed URL phishing technique can make attacks harder to spot 🦿

Hackers are now sending messages that hide fake links in the HTTP prefix, bypassing email filters, says security firm GreatHorn.

πŸ“– Read

via "Tech Republic".
❌ Mysterious Silver Sparrow Malware Found Nesting on 30K Macs ❌

A second malware that targets Macs with Apple's in-house M1 chip is infecting machines worldwide -- but it's unclear why.

πŸ“– Read

via "Threat Post".
❌ Credential-Stuffing Attack Targets Regional Internet Registry ❌

RIPE NCC, the regional Internet registry for Europe, West Asia, and the former Soviet Union, said attackers attempted a credential-stuffing attack against its single-sign on service.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-21512 β€Ό

Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high privileged Cyber Recovery user may potentially exploit this vulnerability leading to the takeover of the notification email account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-9050 β€Ό

Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25171 β€Ό

The affected Fuji Electric V-Server Lite versions prior to 3.3.24.0 are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13549 β€Ό

An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Depending on the vector chosen, an attacker can overwrite service executables and execute arbitrary code with privileges of user set to run the service or replace other files within the installation folder, which would allow for local privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23342 β€Ό

This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. 2) The isURL external check can be bypassed by inserting more Ò€œ////Ҁ� characters

πŸ“– Read

via "National Vulnerability Database".
🦿 Kia outage may be the result of ransomware 🦿

A week-long outage for Kia is reportedly connected to a ransomware attack from the DoppelPaymer gang, says BleepingComputer.

πŸ“– Read

via "Tech Republic".