πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Ransomware Poll: 80% of Victims Don’t Pay Up ❌

Meanwhile, in a separate survey, 80 percent of organizations that paid the ransom said were hit by a second attack.

πŸ“– Read

via "Threat Post".
πŸ•΄ Is an Attacker Living Off Your Land? πŸ•΄

Living-off-the-land attacks pose significant risks to organizations and, on top of that, are difficult to detect. Learn the basics about how these attacks operate and ways to limit their damage.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-20444 β€Ό

Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-22199 β€Ό

SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.

πŸ“– Read

via "National Vulnerability Database".
❌ IKEA Fined $1.2M for Elaborate β€˜Spying System’ ❌

A French court fined the furniture giant for illegal surveillance on 400 customers and staff.

πŸ“– Read

via "Threat Post".
πŸ•΄ Russian National Convicted on Charges Related to Kelihos Botnet πŸ•΄

Oleg Koshkin was arrested in 2019 and faces a maximum penalty of 15 years in prison, the DoJ reports.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Security Flaw Discovered In Peloton Equipment πŸ•΄

The vulnerability could give attackers remote root access to the bike's tablet, researchers report.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Biden Tells Putin Critical Infrastructure Sectors 'Off Limits' to Russian Hacking πŸ•΄

President Joe Biden said he and Russian President Vladimir Putin agreed to discuss boundaries in cyber activity.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-1568 β€Ό

A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to uncontrolled memory allocation. An attacker could exploit this vulnerability by copying a crafted file to a specific folder on the system. A successful exploit could allow the attacker to crash the VPN Agent service when the affected application is launched, causing it to be unavailable to all users of the system. To exploit this vulnerability, the attacker must have valid credentials on a multiuser Windows system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-1541 β€Ό

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Ransomware Operators' Strategies Evolve as Attacks Rise πŸ•΄

Security researchers find ransomware operators rely less on email and more on criminal groups for initial access into target networks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ukraine Police Disrupt Cl0p Ransomware Operation πŸ•΄

Growing list of similar actions in recent months may finally be scaring some operators into quitting, but threat is far from over, security experts say.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-34201 β€Ό

D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, causing the process crashes or changes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34204 β€Ό

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same, and they cannot be modified by normal users. An attacker can easily log in to the target router through the serial port and obtain root privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32243 β€Ό

FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).

πŸ“– Read

via "National Vulnerability Database".
⚠ How to hack a bicycle – Peloton Bike+ rooting bug patched ⚠

It's a bike, Jim, but not as we know it.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-31476 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA templates. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13531.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21777 β€Ό

An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead to an out-of-bounds read.

πŸ“– Read

via "National Vulnerability Database".
❌ Threat Actors Use Google Docs to Host Phishing Attacks ❌

Exploit in the widely used document service leveraged to send malicious links that appear legitimate but actually steal victims credentials.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep37: Quantum crypto, refunding Bitcoins, and Alpaca problems [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
🦿 Amazon Prime Day scams resurface for 2021 🦿

With this year's Amazon Prime Day set for June 21-22, scammers are already touting "Early Prime Day Deals," says Bolster.

πŸ“– Read

via "Tech Republic".