🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2019-18628

Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow a user with administrative privileges to turn off data encryption on the device, thus leaving it open to potential cryptographic information disclosure.

📖 Read

via "National Vulnerability Database".
🦿 How banks and banking customers can protect themselves against financial crimes 🦿

Account takeovers and online banking fraud are two types of attacks on the rise against financial institutions and their customers, says Feedzai.

📖 Read

via "Tech Republic".
🕴 Why We Need More Blue Team Voices at the Table 🕴

The red team draws attention, but the blue team has the expertise to keep networks secure day in and day out.

📖 Read

via "Dark Reading".
CVE-2020-24914

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

📖 Read

via "National Vulnerability Database".
CVE-2020-24912

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

📖 Read

via "National Vulnerability Database".
CVE-2020-24913

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

📖 Read

via "National Vulnerability Database".
CVE-2020-24036

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

📖 Read

via "National Vulnerability Database".
🦿 Report: Quality, not quantity, is the hallmark of the latest waves of phishing attacks 🦿

Cybercriminals have changed tactics since COVID-19, with surgically precise social engineering attacks targeting business apps replacing batch-and-blast phishing.

📖 Read

via "Tech Republic".
🛠 SQLMAP - Automatic SQL Injection Tool 1.5.3 🛠

sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.

📖 Read

via "Packet Storm Security".
COVID-19 Vaccine Spear-Phishing Attacks Jump 26 Percent

Cybercriminals are using the COVID-19 vaccine to steal Microsoft credentials, infect systems with malware and bilk victims out of hundreds of dollars.

📖 Read

via "Threat Post".
🕴 Qualys Is the Latest Victim of Accellion Data Breach 🕴

Security vendor confirms attackers exploited a previously disclosed vulnerability in the enterprise firewall technology to breach its network.

📖 Read

via "Dark Reading".
CISA Orders Federal Agencies to Patch Exchange Servers

Espionage attacks exploiting the just-patched remote code-execution security bugs in Microsoft Exchange servers are quickly spreading.

📖 Read

via "Threat Post".
🕴 New Social Security Scam Spoofs Government Badges 🕴

Criminals text or email photos of fake government identification badges to trick people into sending money.

📖 Read

via "Dark Reading".
CVE-2020-35327

SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php

📖 Read

via "National Vulnerability Database".
CVE-2021-22189

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

📖 Read

via "National Vulnerability Database".
CVE-2020-35328

Courier Management System 1.0 - 'First Name' Stored XSS

📖 Read

via "National Vulnerability Database".
CVE-2021-22183

An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.

📖 Read

via "National Vulnerability Database".
CVE-2020-35329

Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.

📖 Read

via "National Vulnerability Database".
National Surveillance Camera Rollout Roils Privacy Activists

TALON, a network of smart, connected security cameras developed by the Atlanta-based startup and installed by law enforcement around the country, raises surveillance-related privacy concerns.

📖 Read

via "Threat Post".
🕴 Secure Laptops & the Enterprise of the Future 🕴

The enterprise of the future will depend upon organizations' ability to extend the company firewall to everywhere people are working.

📖 Read

via "Dark Reading".
S3 Ep22: Cryptographic escapes and social media scams [Podcast]

Lastest episode - listen now. (And tell your friends!)

📖 Read

via "Naked Security".