πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Crimeware-as-a-service is the latest ransomware threat 🦿

BlackBerry researchers see more double-extortion ransomware attacks, attackers demanding ransom from healthcare patients, and rising bitcoin prices driving the growth of ransomware.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-17457 β€Ό

Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The payload is triggered in the HTTP error response pages.

πŸ“– Read

via "National Vulnerability Database".
🦿 What consumers really think of the upcoming IDFA opt-in, protecting privacy and smartphone data 🦿

App developers need to implement workarounds and create an understanding of the benefits of shared data, according to a new survey from AppsFlyer and Mobile Marketing Association.

πŸ“– Read

via "Tech Republic".
🦿 More than 16 million COVID-themed cyberattacks launched in 2020 🦿

A Trend Micro report found that its system dealt with 16.4 million threats that used COVID-19 as a hook.

πŸ“– Read

via "Tech Republic".
🦿 Eternal Terminal: How to install for persistent SSH connections 🦿

If you have trouble with SSH connections breaking, Jack Wallen shows you how you can enjoy a bit more persistence with the help of Eternal Terminal.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2019-18235 β€Ό

Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-18231 β€Ό

Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-18233 β€Ό

In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.

πŸ“– Read

via "National Vulnerability Database".
❌ Cisco Plugs Security Hole in Small Business Routers ❌

The Cisco security vulnerability exists in the RV132W ADSL2+ Wireless-N VPN Routers and RV134W VDSL2 Wireless-AC VPN Routers.

πŸ“– Read

via "Threat Post".
❌ Teen Behind Twitter Bit-Con Breach Cuts Plea Deal ❌

The β€˜young mastermind’ of the Twitter hack will serve three years in juvenile detention. 

πŸ“– Read

via "Threat Post".
πŸ•΄ RDP Attacks Persist Near Record Levels in 2021 πŸ•΄

A wave of attacks targeting Remote Desktop Protocol has continued throughout the pandemic as more employees continue to work from home.

πŸ“– Read

via "Dark Reading".
🦿 Free hack_it event aims to help cybersecurity pros hone their skills 🦿

Attendees will explore the mind of a hacker, role play and share real-world experiences at the free two-day event hosted by Huntress.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Mimecast Says SolarWinds Attackers Accessed its Source Code Repositories πŸ•΄

But the amount of code downloaded is too little to be of any use, the email security vendor says in its latest update.

πŸ“– Read

via "Dark Reading".
⚠ Bitcoin scammer who hacked celeb Twitter accounts gets 3 years ⚠

Youngster behind blue-flag Twitter hack of Elon Musk, Bill Gates, Apple Inc. and many others will do three years in prison.

πŸ“– Read

via "Naked Security".
⚠ Serious Security: The Linux kernel bugs that surfaced after 15 years ⚠

Anyone could have found these bugs, but everyone assumed someone would, and in the end, no one did. (Until now.)

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-20629 β€Ό

Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20634 β€Ό

Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Custom App via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20633 β€Ό

Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Cabinet via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20675 β€Ό

M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) versions prior to Ver3.0, type D (DL8-D) versions prior to Ver3.0, and type E (DL8-E) versions prior to Ver3.0) allows remote authenticated attackers to cause a denial of service (DoS) condition via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20630 β€Ό

Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Phone Messages via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20627 β€Ό

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".