🛡 Cybersecurity & Privacy 🛡 - News
26.3K subscribers
89.4K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2021-21193

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
CVE-2021-21192

Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
CVE-2021-21191

Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
CVE-2020-4851

IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190450.

📖 Read

via "National Vulnerability Database".
🕴 Software Development Security Firm Argon Announces Launch 🕴

Check Point founder Shlomo Kramer is one of the firm's investors.

📖 Read

via "Dark Reading".
🦿 99.2% of US government Android users are running outdated OS versions 🦿

Some versions of Android in use by government employees go all the way back to 2017's Android 8, and that's a huge cybersecurity problem.

📖 Read

via "Tech Republic".
Exchange Cyberattacks Escalate as Microsoft Rolls One-Click Fix

Public proof-of-concept (PoC) exploits for ProxyLogon could be fanning a feeding frenzy of attacks even as patching makes progress.

📖 Read

via "Threat Post".
Magecart Attackers Save Stolen Credit-Card Data in .JPG File

Researchers from Sucuri discovered the tactic, which creatively hides malicious activity until the info can be retrieved, during an investigation into a compromised Magento 2 e-commerce site.

📖 Read

via "Threat Post".
Latest Mirai Variant Targets SonicWall, D-Link and IoT Devices

A new Mirai variant is targeting known flaws in D-Link, Netgear and SonicWall devices, as well as newly-discovered flaws in unknown IoT devices.

📖 Read

via "Threat Post".
🕴 Best Practices for Securing Service Accounts 🕴

While service accounts solve many of the challenges presented by automation, they can also create serious problems when it comes to cybersecurity.

📖 Read

via "Dark Reading".
🕴 Microsoft Releases Mitigation Tool for On-Premises Exchange Servers 🕴

The tool, developed for organizations without dedicated IT and security teams, is meant to be used as temporary mitigation.

📖 Read

via "Dark Reading".
🦿 Mamma Mia! Compromised passwords are filled with popular music artists 🦿

All apologies, but if you use your favorite band as part of your password it's time to turn around and try something else.

📖 Read

via "Tech Republic".
🦿 McAfee uncovers espionage campaign aimed at major telecommunication companies 🦿

The security company said the attacks were attributed to RedDelta and Mustang Panda, both of which are allegedly based in China.

📖 Read

via "Tech Republic".
CVE-2020-28899

The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.

📖 Read

via "National Vulnerability Database".
CVE-2021-22887

A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.

📖 Read

via "National Vulnerability Database".
CVE-2021-25916

Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

📖 Read

via "National Vulnerability Database".
CVE-2021-27938

A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.

📖 Read

via "National Vulnerability Database".
🕴 IronNet Cybersecurity to Go Public in Merger 🕴

Company intends for the deal to drive adoption of its Collective Defense Platform.

📖 Read

via "Dark Reading".
🦿 Bitwarden: How to enable biometric login 🦿

If you'd rather not have to enter your password every time you open the Bitwarden password manager on your mobile device, Jack Wallen shows you how to enable biometric login.

📖 Read

via "Tech Republic".
Mom & Daughter Duo Hack Homecoming Crown

A Florida high-school student faces jail time for rigging her school's Homecoming Queen election.

📖 Read

via "Threat Post".
PYSA Ransomware Pillages Education Sector, Feds Warn

A major spike of attacks against higher ed, K-12 and seminaries in March has prompted the FBI to issue a special alert.

📖 Read

via "Threat Post".