🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2020-35327

SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php

📖 Read

via "National Vulnerability Database".
CVE-2021-22189

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

📖 Read

via "National Vulnerability Database".
CVE-2020-35328

Courier Management System 1.0 - 'First Name' Stored XSS

📖 Read

via "National Vulnerability Database".
CVE-2021-22183

An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.

📖 Read

via "National Vulnerability Database".
CVE-2020-35329

Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.

📖 Read

via "National Vulnerability Database".
National Surveillance Camera Rollout Roils Privacy Activists

TALON, a network of smart, connected security cameras developed by the Atlanta-based startup and installed by law enforcement around the country, raises surveillance-related privacy concerns.

📖 Read

via "Threat Post".
🕴 Secure Laptops & the Enterprise of the Future 🕴

The enterprise of the future will depend upon organizations' ability to extend the company firewall to everywhere people are working.

📖 Read

via "Dark Reading".
S3 Ep22: Cryptographic escapes and social media scams [Podcast]

Lastest episode - listen now. (And tell your friends!)

📖 Read

via "Naked Security".
🔏 New AI System Could Deter IP Theft 🔏

A new artificial intelligence system developed by Dartmouth students can create fake documents to fool hackers and curb IP theft.

📖 Read

via "Digital Guardian".
🦿 How to work with Vault Secrets Engines 🦿

Jack Wallen shows you how to create both local and AWS secrets engines with Hashicorp's Vault.

📖 Read

via "Tech Republic".
Cyberattackers Target Top Russian Cybercrime Forums

Elite Russian forums for cybercriminals have been hacked in a string of breaches, leaving hackers edgy and worried about law enforcement.  

📖 Read

via "Threat Post".
Microsoft, FireEye Unmask More Malware Linked to SolarWinds Attackers

Researchers with Microsoft and FireEye found three new malware families, which they said are used by the threat group behind the SolarWinds attack.

📖 Read

via "Threat Post".
🕴 Microsoft, FireEye Uncover More Malware Used in the SolarWinds Campaign 🕴

Newly discovered tools were designed for late-stage use after the attackers had already established a relatively firm presence on a breached network, vendors say.

📖 Read

via "Dark Reading".
🕴 Healthcare Still Seeing High Level of Attacker Activity 🕴

Interest in vaccines is driving all sorts of activity, reports say, from vaccine-specific phishing to growing bot traffic on healthcare sites.

📖 Read

via "Dark Reading".
🕴 Business Apps Spoofed in 45% of Impersonation Attacks 🕴

Business-related applications like those from Microsoft, Zoom, and DocuSign are most often impersonated in brand phishing attacks.

📖 Read

via "Dark Reading".
CVE-2021-25331

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.

📖 Read

via "National Vulnerability Database".
CVE-2021-25338

Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region.

📖 Read

via "National Vulnerability Database".
CVE-2021-25332

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.

📖 Read

via "National Vulnerability Database".
CVE-2021-25348

Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.

📖 Read

via "National Vulnerability Database".
CVE-2021-25342

Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.

📖 Read

via "National Vulnerability Database".
CVE-2021-25345

Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format.

📖 Read

via "National Vulnerability Database".