πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2017-3905 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
❌ REvil Hits US Nuclear Weapons Contractor: Report ❌

"We hereby keep a right (sic) to forward all of the relevant documentation and data to military agencies of our choise (sic)" REvil reportedly wrote.

πŸ“– Read

via "Threat Post".
❌ Baby Clothes Giant Carter’s Leaks 410K Customer Records ❌

Purchase automation software delivered shortened URLs without protections.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-22753 β€Ό

A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22915 β€Ό

Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0491 β€Ό

In memory management driver, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-183461315

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23204 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to Command Centre Operators. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ McDonald's Data Breach Exposed Business & Customer Data πŸ•΄

An investigation has revealed company data has been breached in the United States, South Korea, and Taiwan.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-27200 β€Ό

In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Trickbot Investigation Shows Details of Massive Cybercrime Effort πŸ•΄

Nearly a score of cybercriminals allegedly worked together to create the Trickbot malware and deploy it against more than a million users, an unsealed indictment claims.

πŸ“– Read

via "Dark Reading".
❌ Unpatched Bugs Found Lurking in Provisioning Platform Used with Cisco UC ❌

A trio of security flaws open the door to remote-code execution and a malware tsunami.

πŸ“– Read

via "Threat Post".
🦿 McDonald's suffers cyberattack in US, South Korea and Taiwan 🦿

The restaurant chain reportedly said no U.S. customer data was exposed and the attack did not involve ransomware.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2017-5730 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-5755 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-3918 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-3913 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-3919 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-5690 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34679 β€Ό

Thycotic Password Reset Server before 5.3.0 allows credential disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-5765 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-12909 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

πŸ“– Read

via "National Vulnerability Database".