πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-32514 β€Ό

Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Releases Emergency Patch for 'PrintNightmare' Flaw πŸ•΄

Urges Organizations to immediately apply security update citing exploit activity.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Are Security Attestations a Necessity for SaaS Businesses? πŸ•΄

Are security attestations becoming business imperatives, or are they merely token additions on the list of regulatory requirements?

πŸ“– Read

via "Dark Reading".
🦿 Bitwarden has a new Send feature: Here's how to use it 🦿

This tool will make this productβ€”probably the best password manager on the marketβ€”even better.

πŸ“– Read

via "Tech Republic".
❌ MacOS Targeted in WildPressure APT Malware Campaign ❌

Threat actors enlist compromised WordPress websites in campaign targeting macOS users.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-20416 β€Ό

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 196218.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20415 β€Ό

IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.

πŸ“– Read

via "National Vulnerability Database".
🦿 What to do when 2FA won't allow you into your Linux servers 🦿

If two-factor authentication logins on your Linux servers are giving you fits, Jack Wallen has the solution for you.

πŸ“– Read

via "Tech Republic".
❌ Critical Sage X3 RCE Bug Allows Full System Takeovers ❌

Security vulnerabilities in the ERP platform could allow attackers to tamper with or sabotage victims' business-critical processes and to intercept data.

πŸ“– Read

via "Threat Post".
πŸ•΄ Sophos Acquires Capsule8 for Linux Server & Container Security πŸ•΄

The deal was announced the same day ZeroFox bought Dark Web intelligence firm Vigilante as a wave of security M&A continues.

πŸ“– Read

via "Dark Reading".
πŸ” Changes to Nevada's Privacy Law Includes Requirements for Data Brokers πŸ”

Recent changes to Nevada’s privacy law, effective October 1, 2021, give residents a broader right to opt out of sales and puts the onus on "data brokers" to respond to such requests.

πŸ“– Read

via "".
πŸ•΄ Fake Android Apps Promise Cryptomining Services to Steal Funds πŸ•΄

Researchers discover more than 170 Android apps that advertise cloud cryptocurrency mining services and fail to deliver.

πŸ“– Read

via "Dark Reading".
🦿 $13.7 million: Atlas VPN adds up the impact of the top 10 most successful blockchain scams 🦿

A new report finds that fake investment scams have netted the most funds among all the types of active blockchain scams.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-23702 β€Ό

Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36217 β€Ό

Avahi 0.8 allows a local denial of service (NULL pointer dereference and daemon crash) against avahi-daemon via the D-Bus interface or a "ping .local" command.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours πŸ•΄

Automation allowed a REvil affiliate to move from exploitation of vulnerable servers to installing ransomware on downstream companies faster than most defenders could react.

πŸ“– Read

via "Dark Reading".
🦿 Scammers exploiting Kaseya ransomware attack to deploy malware 🦿

A new phishing campaign claims to offer a security update for Kaseya's VSA software but actually tries to install malware, says Malwarebytes.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-32714 β€Ό

hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in "request smuggling" or "desync attacks." The vulnerability is patched in version 0.14.10. Two possible workarounds exist. One may reject requests manually that contain a `Transfer-Encoding` header or ensure any upstream proxy rejects `Transfer-Encoding` chunk sizes greater than what fits in 64-bit unsigned integers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2007-5002 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21775 β€Ό

A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21807 β€Ό

An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".