πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-32575 β€Ό

HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33557 β€Ό

An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.

πŸ“– Read

via "National Vulnerability Database".
❌ Clop Raid: A Big Win in the War on Ransomware? ❌

Cops arrest six, seize cars and cash in splashy raid, and experts are applauding.

πŸ“– Read

via "Threat Post".
πŸ•΄ Google Launches SLSA, A New Framework for Supply Chain Integrity πŸ•΄

The 'Supply chain Levels for Software Artifacts' aims to ensure the integrity of components throughout the software supply chain.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Carnival Cruise Line Reports Security Breach πŸ•΄

The cruise ship operator says the incident affected employee and guest data.

πŸ“– Read

via "Dark Reading".
πŸ•΄ One in Five Manufacturing Firms Targeted by Cyberattacks πŸ•΄

Information-stealing malware makes up about a third of attacks, a study finds, but companies worry most about ransomware shutting down production.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-32695 β€Ό

Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.16.1, a malicious app on the same device could have gotten access to the shared preferences of the Nextcloud Android application. This required user-interaction as a victim had to initiate the sharing flow and choose the malicious app. The shared preferences contain some limited private data such as push tokens and the account name. The vulnerability is patched in version 3.16.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Data Breaches Surge in Food & Beverage, Other Industries πŸ•΄

Six previously "under-attacked" vertical industries saw a surge in data breaches last year due to COVID-19 related disruptions and other factors, new data shows.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-32426 β€Ό

In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32694 β€Ό

Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the same device is possible to crash the Nextcloud Android Client due to an uncaught exception. The vulnerability is patched in version 3.15.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34811 β€Ό

Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34553 β€Ό

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 6/18 πŸ”

New data privacy acts, the G7 on ransomware, and how cybersecurity factors into M&As - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "".
🦿 Microsoft's new security tool will discover firmware vulnerabilities, and more, in PCs and IoT devices 🦿

Devices have multiple OSs and firmware running, and most organisations don't know what they have or if it's secure. Microsoft will use ReFirm to make it easier to find out without being an expert.

πŸ“– Read

via "Tech Republic".
❌ Faux β€˜DarkSide’ Gang Takes Aim at Global Energy, Food Sectors ❌

A DarkSide doppelganger mounts a fraud campaign aimed at extorting nearly $4 million from each target.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-33576 β€Ό

An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32536 β€Ό

The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
❌ β€˜Oddball’ Malware Blocks Access to Pirated Software ❌

Rather than steal credentials or hold data for ransom, a recent campaign observed by Sophos prevents people from visiting sites that offer illegal downloads.

πŸ“– Read

via "Threat Post".
❌ Insider Versus Outsider: Navigating Top Data Loss Threats ❌

Troy Gill, manager of security research at Zix, discusses the most common ways sensitive data is scooped up by nefarious sorts.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2005-0394 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26834 β€Ό

A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code execution will happen immediately on markdown view mode.

πŸ“– Read

via "National Vulnerability Database".