πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Microsoft rolls out emergency patch for critical PrintNightmare flaw 🦿

Fixing a serious security hole in the Windows Print spooler service, the patch is available for almost all versions of Windows, even Windows 7.

πŸ“– Read

via "Tech Republic".
❌ Why I Love (Breaking Into) Your Security Appliances ❌

David "moose" Wolpoff, CTO at Randori, discusses security appliances and VPNs and how attackers only have to "pick one lock" to invade an enterprise through them.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-34623 β€Ό

A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34624 β€Ό

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22555 β€Ό

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36212 β€Ό

app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.

πŸ“– Read

via "National Vulnerability Database".
❌ Fake Kaseya VSA Security Update Drops Cobalt Strike ❌

Threat actors are planting Cobalt Strike backdoors by malspamming a bogus Microsoft update along with a SecurityUpdates.exe.

πŸ“– Read

via "Threat Post".
πŸ•΄ Security 101: The 'PrintNightmare' Flaw πŸ•΄

A closer look at the printer software vulnerability - and what you can do about it.

πŸ“– Read

via "Dark Reading".
🦿 Critical flaws in Windows Print spooler service could allow for remote attacks 🦿

Administrators are urged to apply the latest patches from Microsoft and disable the Windows Print spooler service in domain controllers and systems not used for printing.

πŸ“– Read

via "Tech Republic".
🦿 Critical flaws in Windows Print spooler service could allow for remote attacks 🦿

Administrators are urged to apply the latest patches from Microsoft and disable the Windows Print spooler service in domain controllers and systems not used for printing.

πŸ“– Read

via "Tech Republic".
πŸ›  Zeek 4.0.3 πŸ› 

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. While focusing on network security monitoring, Zeek provides a comprehensive platform for more general network traffic analysis as well. Well grounded in more than 15 years of research, Zeek has successfully bridged the traditional gap between academia and operations since its inception. Today, it is relied upon operationally in particular by many scientific environments for securing their cyber-infrastructure. Zeek's user community includes major universities, research labs, supercomputing centers, and open-science communities. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
❌ Suspected β€˜Dr HeX’ Hacker Busted for 9 Years of Phishing ❌

The unnamed suspect allegedly helped to develop carding and phishing kits with the aim of stealing customers' bank-card data.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-24143 β€Ό

Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20211 β€Ό

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32535 β€Ό

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administratorÒ€ℒs permission and execute arbitrary functions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32514 β€Ό

Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Releases Emergency Patch for 'PrintNightmare' Flaw πŸ•΄

Urges Organizations to immediately apply security update citing exploit activity.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Are Security Attestations a Necessity for SaaS Businesses? πŸ•΄

Are security attestations becoming business imperatives, or are they merely token additions on the list of regulatory requirements?

πŸ“– Read

via "Dark Reading".
🦿 Bitwarden has a new Send feature: Here's how to use it 🦿

This tool will make this productβ€”probably the best password manager on the marketβ€”even better.

πŸ“– Read

via "Tech Republic".
❌ MacOS Targeted in WildPressure APT Malware Campaign ❌

Threat actors enlist compromised WordPress websites in campaign targeting macOS users.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-20416 β€Ό

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 196218.

πŸ“– Read

via "National Vulnerability Database".