πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Don’t get tricked by this crashtastic iPhone Wi-Fi hack! ⚠

Learn how the trick works so that you can avoid it in case someone thinks it's a joke to catch you out.

πŸ“– Read

via "Naked Security".
πŸ•΄ Enterprises Altering Their Supply Chain Defenses on Heels of Latest Breaches πŸ•΄

More than half of enterprises surveyed for Dark Reading's State of Malware Threats report indicate they are making at least a few changes to their supply chain security defenses following recent attacks on software vendors such as SolarWinds.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-36123 β€Ό

An issue was discovered in Echo ShareCare 8.15.5. The TextReader feature in General/TextReader/TextReader.cfm is susceptible to a local file inclusion vulnerability when processing remote input in the textFile parameter from an authenticated user, leading to the ability to read arbitrary files on the server filesystems as well any files accessible via Universal Naming Convention (UNC) paths.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-22875 β€Ό

Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
❌ β€˜Charming Kitten’ APT Siphons Intel From Mid-East Scholars ❌

Professors, journalists and think-tank personnel, beware strangers bearing webinars: It’s the focus of a particularly sophisticated, and chatty, phishing campaign.

πŸ“– Read

via "Threat Post".
πŸ•΄ Why We Need to Raise the Red Flag Against FragAttacks πŸ•΄

Proliferation of wireless devices increases the risk that corporate networks will be attacked with this newly discovered breed of Wi-Fi-based cyber assault.

πŸ“– Read

via "Dark Reading".
🦿 Bad actor offers up for sale data from 600 million LinkedIn members scraped from the site 🦿

Cyber News reports that this is the third time in four months that member information has shown up on a hacker forum.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-20362 β€Ό

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195033.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20366 β€Ό

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195037.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ DoD-Validated Data Security Startup Emerges From Stealth πŸ•΄

The Code-X platform has been tested by the US Department of Defense and members of the intelligence community.

πŸ“– Read

via "Dark Reading".
❌ Adobe Patches 11 Critical Bugs in Popular Acrobat PDF Reader ❌

Adobe July patch roundup includes fixes for its ubiquitous and free PDF reader Acrobat 2020 and other software such as Illustrator and Bridge.

πŸ“– Read

via "Threat Post".
❌ Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers ❌

The 'ModiPwn' bug lays open production lines, sensors, conveyor belts, elevators, HVACs and more that use Schneider Electric PLCs.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-31217 β€Ό

In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36214 β€Ό

LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.

πŸ“– Read

via "National Vulnerability Database".
❌ Guess Fashion Brand Deals With Data Loss After Ransomware Attack ❌

An attack on Guess compromised the personal and banking data of 1,300 victims.

πŸ“– Read

via "Threat Post".
❌ Ransomware Giant REvil’s Sites Disappear ❌

Just days after President Biden demanded that Russian President Putin shut down ransomware groups, the servers of one of the biggest groups mysteriously went dark.

πŸ“– Read

via "Threat Post".
❌ Microsoft Crushes 116 Bugs, Three Actively Exploited ❌

Microsoft tackles 12 critical bugs, part of its July 2021 Patch Tuesday roundup, capping a β€˜PrintNightmare’ month of headaches for system admins.

πŸ“– Read

via "Threat Post".
πŸ•΄ Microsoft Patches 3 Windows Zero-Days Amid 117 CVEs πŸ•΄

The July Patch Tuesday release also includes the out-of-band fix for the Windows Print Spooler remote code execution flaw under attack.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-32755 β€Ό

Wire is a collaboration platform. wire-ios-transport handles authentication of requests, network failures, and retries for the iOS implementation of Wire. In the 3.82 version of the iOS application, a new web socket implementation was introduced for users running iOS 13 or higher. This new websocket implementation is not configured to enforce certificate pinning when available. Certificate pinning for the new websocket is enforced in version 3.84 or above.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ New Phishing Campaign Targets Individuals of Interest to Iran πŸ•΄

TA453 group spoofed two scholars at University of London to try and gain access to email inboxes belonging to journalists, think tank personnel, academics, and others, security vendor says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-19721 β€Ό

A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while running mp42aac, leading to system crashes and a denial of service (DOS).

πŸ“– Read

via "National Vulnerability Database".