πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-21807 β€Ό

An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34430 β€Ό

Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28809 β€Ό

An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31817 β€Ό

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31816 β€Ό

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

πŸ“– Read

via "National Vulnerability Database".
🦿 Ransomware: Top 5 more things to know 🦿

Ransomware attacks are getting bigger and harder to defend against. Tom Merritt lists five more things about ransomware you need to know.

πŸ“– Read

via "Tech Republic".
πŸ•΄ What Colonial Pipeline Means for Commercial Building Cybersecurity πŸ•΄

Banks and hospitals may be common targets, but now commercial real estate must learn to protect itself against stealthy hackers.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-21779 β€Ό

A use-after-free vulnerability exists in the way WebkitÒ€ℒs GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The NSA's 'New' Mission: Get More Public With the Private Sector πŸ•΄

The National Security Agency's gradual emergence from the shadows was "inevitable" in cybersecurity, says Vinnie Liu, co-founder and CEO of offensive security firm Bishop Fox and a former NSA analyst. Now the agency has to figure out how to best work with the private sector, especially organizations outside the well-resourced and seasoned Fortune 100.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Kaseya Hacked via Authentication Bypass πŸ•΄

The Kaseya ransomware attack is believed to have been down to an authentication bypass. Yes, ransomware needs to be on your radar -- but good authentication practices are also imperative.

πŸ“– Read

via "Dark Reading".
🦿 Android app users targeted with cryptomining scams 🦿

Found on Google Play and third-party app stores, the apps discovered by Lookout stole an estimated $350,000 from more than 93,000 people.

πŸ“– Read

via "Tech Republic".
🦿 77% of executives plan to hire in the months ahead, according to a new poll 🦿

West Monroe's executive poll details third-quarter hiring expectations, cybersecurity preparedness, investments to digitize business operations and more.

πŸ“– Read

via "Tech Republic".
🦿 "Black Widow" digital premier a cover for malware and scams, says Kaspersky 🦿

Phishing, malicious files and other forms of fraud have followed the highly awaited movie since it was first delayed due to COVID-19. On the eve of its actual release, the scams have begun anew.

πŸ“– Read

via "Tech Republic".
❌ How Fake Accounts and Sneaker-Bots Took Over the Internet ❌

Jason Kent, hacker-in-residence at Cequence Security, discusses fake online accounts, and the fraud they carry out on a daily basis.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-29150 β€Ό

A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25440 β€Ό

Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an escalated privilege.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25439 β€Ό

Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.

πŸ“– Read

via "National Vulnerability Database".
⚠ PrintNightmare official patch is out – update now! ⚠

Patch now! This security hole could allow almost anyone to take over your whole network from almost any account on almost any computer.

πŸ“– Read

via "Naked Security".
🦿 Microsoft patches remaining versions of Windows against PrintNightmare flaw 🦿

Patches to fix a severe flaw in the Windows Print spooler are now available for Windows 10 Version 1607, Windows Server 2012 and Windows Server 2016.

πŸ“– Read

via "Tech Republic".
❌ Coursera Flunks API Security Test in Researchers’ Exam ❌

The problem APIs included numero uno on the OWASP API Security Top 10: a Broken Object Level Authorization (BOLA) issue that could have exposed personal data.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-29711 β€Ό

IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Force ID: 200965.

πŸ“– Read

via "National Vulnerability Database".