πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 IoT projects demand new skills from IT project managers 🦿

If you think regular IT project managers can run IoT projects, you might be miscalculating. Here's why.

πŸ“– Read

via "Tech Republic".
❌ Linux-Focused Cryptojacking Gang Tracked to Romania ❌

The gang is using a new brute-forcer – β€œDiicot brute” – to crack passwords on Linux-based machines with weak passwords.

πŸ“– Read

via "Threat Post".
πŸ•΄ Did the Cybersecurity Workforce Gap Distract Us From the Leak? πŸ•΄

Cyber games can play a critical role in re-engaging our workforce and addressing the employee retention crisis.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-29147 β€Ό

A SQL injection vulnerability in wy_controlls/wy_side_visitor.php of Wayang-CMS v1.0 allows attackers to obtain sensitive database information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36740 β€Ό

Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.

πŸ“– Read

via "National Vulnerability Database".
❌ Cryptominer Farm Rigged with 3,800 PS4s Busted in Ukraine ❌

Ukrainian cops seize PlayStation 4 consoles, graphics cards, processors and more in cryptomining sting involving alleged electricity theft.

πŸ“– Read

via "Threat Post".
🦿 Kaspersky: LuminousMoth spearphishing campaign hit 1,500 targets in Asia 🦿

Security researchers think HoneyMyte is behind the advanced persistent threat that has mostly targeted government entities.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-34514 β€Ό

Windows Kernel Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-31979, CVE-2021-33771.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33746 β€Ό

Windows DNS Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-33754, CVE-2021-33780, CVE-2021-34494, CVE-2021-34525.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34490 β€Ό

Windows TCP/IP Driver Denial of Service Vulnerability This CVE ID is unique from CVE-2021-31183, CVE-2021-33772.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34473 β€Ό

Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33774 β€Ό

Windows Event Tracing Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33768 β€Ό

Microsoft Exchange Server Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-34470, CVE-2021-34523.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33778 β€Ό

HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31947, CVE-2021-33775, CVE-2021-33776, CVE-2021-33777.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Targeted Attack Activity Heightens Need for Orgs. to Patch New SolarWinds Flaw πŸ•΄

A China-based threat actor -- previously observed targeting US defense industrial base organizations and software companies -- is exploiting the bug in SolarWinds' Serv-U software, Microsoft says.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google to Bring HTTPS-First Mode to Chrome Browser πŸ•΄

Beginning in M94, Chrome will offer HTTPS-First Mode, which will attempt to upgrade all page loads to HTTPS.

πŸ“– Read

via "Dark Reading".
🦿 Tokyo 2020 Olympics must be extra secure to avoid cyberattacks and ransomware 🦿

Any big event is likely to attract bad actors. Keeping the games safe from attack is a huge undertaking for event planners.

πŸ“– Read

via "Tech Republic".
🦿 Tokyo 2020 Olympics must be extra secure to avoid cyberattacks and ransomware 🦿

Any big event is likely to attract bad actors. Keeping the games safe from attack is a huge undertaking for event planners.

πŸ“– Read

via "Tech Republic".
πŸ•΄ SonicWall: 'Imminent' Ransomware Attack Targets Older Products πŸ•΄

The attack exploits a known vulnerability that was fixed in new versions of firmware released this year.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-29157 β€Ό

An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system is restarted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22867 β€Ό

A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.1.3 and was fixed in 3.1.3, 3.0.11, and 2.22.17. This vulnerability was reported via the GitHub Bug Bounty program.

πŸ“– Read

via "National Vulnerability Database".