πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Insider Versus Outsider: Navigating Top Data Loss Threats ❌

Troy Gill, manager of security research at Zix, discusses the most common ways sensitive data is scooped up by nefarious sorts.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2005-0394 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26834 β€Ό

A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code execution will happen immediately on markdown view mode.

πŸ“– Read

via "National Vulnerability Database".
❌ Carnival Cruise Cyber-Torpedoed by Cyberattack ❌

This is the fourth time in a bit over a year that Carnival’s admitted to breaches, with two of them being ransomware attacks.

πŸ“– Read

via "Threat Post".
❌ What’s Making Your Company a Ransomware Sitting Duck ❌

What's the low-hanging fruit for ransomware attackers? What steps could help to fend them off, and what’s stopping organizations from implementing those steps?

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-3604 β€Ό

Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection. An attacker could exploit this vulnerability in order to extract information of users and administrator accounts stored in the database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18442 β€Ό

Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 11 Security Certifications to Seek Out This Summer πŸ•΄

The more you know, the more you grow. The Edge takes a fresh look at leading security certifications that can help advance your security career.

πŸ“– Read

via "Dark Reading".
⚠ Can *YOU* blow a PC speaker using only a Linux kernel driver? ⚠

Can you help? There's a hidden meaning here, and it's time to find it!

πŸ“– Read

via "Naked Security".
⚠ S3 Ep37: Quantum crypto, refunding Bitcoins, and Alpaca problems [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-33818 β€Ό

An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Accidental Insider Leaks Prove Major Source of Risk πŸ•΄

Research reports highlight growing concerns around insider negligence that leads to data breaches.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Attackers Find New Way to Exploit Google Docs for Phishing πŸ•΄

Tactic continues recent trend by attackers to use trusted cloud services to send and host malicious content.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-33823 β€Ό

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33824 β€Ό

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31272 β€Ό

SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31662 β€Ό

RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33186 β€Ό

SerenityOS in test-crypto.cpp contains a stack buffer overflow which could allow attackers to obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24368 β€Ό

The Quiz And Survey Master ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20467 β€Ό

White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attackers can exploit the vulnerability to create a task.

πŸ“– Read

via "National Vulnerability Database".