πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground ❌

After 500 million LinkedIn enthusiasts were affected in a data-scraping incident in April, it's happened again - with big security ramifications.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-1134 β€Ό

A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation of the X.509 certificate used when establishing a connection between DNA Center and an ISE server. An attacker could exploit this vulnerability by supplying a crafted certificate and could then intercept communications between the ISE and DNA Center. A successful exploit could allow the attacker to view and alter sensitive information that the ISE maintains about clients that are connected to the network.

πŸ“– Read

via "National Vulnerability Database".
❌ Cobalt Strike Usage Explodes Among Cybercrooks ❌

The legit security tool has shown up 161 percent more, year-over-year, in cyberattacks, having β€œgone fully mainstream in the crimeware world.”

πŸ“– Read

via "Threat Post".
❌ Details of RCE Bug in Adobe Experience Manager Revealed ❌

Disclosure of a bug in Adobe’s content-management solution - used by Mastercard, LinkedIn and PlayStation – were released.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-33503 β€Ό

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34548 β€Ό

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

πŸ“– Read

via "National Vulnerability Database".
🦿 Americans lost $29.8 billion to phone scams in the past year, study finds 🦿

The number of spam calls, the number of people losing money to them and the total amount of money lost In the past year are all record setting.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 3 Ways Cybercriminals Are Undermining MFA πŸ•΄

Using multifactor authentication is an excellent security step, but like everything else, it is not foolproof and will never be 100% effective.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-23400 β€Ό

The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7871 β€Ό

A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of the parameter. This issue affects: Cnesty Helpcom 10.0 versions prior to.

πŸ“– Read

via "National Vulnerability Database".
🦿 Security and automation are top priorities for IT professionals 🦿

Data protection and lack of budgets and resources continue to present the biggest challenges as cyberattacks increase, according to a new Kaseya report.

πŸ“– Read

via "Tech Republic".
πŸ›  Proxmark 4.13441 πŸ› 

This is a custom firmware written for the Proxmark3 device. It extends the currently available firmware.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2020-7868 β€Ό

A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32992 β€Ό

FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory buffer, which may allow an attacker to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31505 β€Ό

This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-12890.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7870 β€Ό

A memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to insufficient validation of the parameter.

πŸ“– Read

via "National Vulnerability Database".
🦿 How to give users sudo privileges on Ubuntu and Red Hat-based Linux distributions in Linux 🦿

New Linux admins need to know how to give and take sudo privileges from users. Jack Wallen shows you how on both Ubuntu- and Red Hat-based Linux distributions.

πŸ“– Read

via "Tech Republic".
❌ Microsoft Translation Bugs Open Edge Browser to Trivial UXSS Attacks ❌

The bug in Edge's auto-translate could have let remote attackers pull off RCE on any foreign-language website just by sending a message with an XSS payload.

πŸ“– Read

via "Threat Post".
πŸ•΄ Technology's Complexity and Opacity Threaten Critical Infrastructure Security πŸ•΄

Addressing the complexity of modern distributed software development is one of the most important things we can do to decrease supply chain risk.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-20104 β€Ό

Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20105 β€Ό

Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.

πŸ“– Read

via "National Vulnerability Database".