πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-34811 β€Ό

Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34553 β€Ό

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 6/18 πŸ”

New data privacy acts, the G7 on ransomware, and how cybersecurity factors into M&As - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "".
🦿 Microsoft's new security tool will discover firmware vulnerabilities, and more, in PCs and IoT devices 🦿

Devices have multiple OSs and firmware running, and most organisations don't know what they have or if it's secure. Microsoft will use ReFirm to make it easier to find out without being an expert.

πŸ“– Read

via "Tech Republic".
❌ Faux β€˜DarkSide’ Gang Takes Aim at Global Energy, Food Sectors ❌

A DarkSide doppelganger mounts a fraud campaign aimed at extorting nearly $4 million from each target.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-33576 β€Ό

An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32536 β€Ό

The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
❌ β€˜Oddball’ Malware Blocks Access to Pirated Software ❌

Rather than steal credentials or hold data for ransom, a recent campaign observed by Sophos prevents people from visiting sites that offer illegal downloads.

πŸ“– Read

via "Threat Post".
❌ Insider Versus Outsider: Navigating Top Data Loss Threats ❌

Troy Gill, manager of security research at Zix, discusses the most common ways sensitive data is scooped up by nefarious sorts.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2005-0394 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26834 β€Ό

A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code execution will happen immediately on markdown view mode.

πŸ“– Read

via "National Vulnerability Database".
❌ Carnival Cruise Cyber-Torpedoed by Cyberattack ❌

This is the fourth time in a bit over a year that Carnival’s admitted to breaches, with two of them being ransomware attacks.

πŸ“– Read

via "Threat Post".
❌ What’s Making Your Company a Ransomware Sitting Duck ❌

What's the low-hanging fruit for ransomware attackers? What steps could help to fend them off, and what’s stopping organizations from implementing those steps?

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-3604 β€Ό

Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection. An attacker could exploit this vulnerability in order to extract information of users and administrator accounts stored in the database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18442 β€Ό

Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 11 Security Certifications to Seek Out This Summer πŸ•΄

The more you know, the more you grow. The Edge takes a fresh look at leading security certifications that can help advance your security career.

πŸ“– Read

via "Dark Reading".
⚠ Can *YOU* blow a PC speaker using only a Linux kernel driver? ⚠

Can you help? There's a hidden meaning here, and it's time to find it!

πŸ“– Read

via "Naked Security".
⚠ S3 Ep37: Quantum crypto, refunding Bitcoins, and Alpaca problems [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-33818 β€Ό

An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Accidental Insider Leaks Prove Major Source of Risk πŸ•΄

Research reports highlight growing concerns around insider negligence that leads to data breaches.

πŸ“– Read

via "Dark Reading".