πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Cisco Issues Critical Fixes for High-End Nexus Gear ❌

Networking giant issues two critical patches and six high-severity patches.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-37334 β€Ό

A security issue in Umbraco Forms 4.0.0 to and including 8.7.5 could lead to a remote code execution attack and/or arbitrary file deletion.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft Breaks Silence on Barrage of ProxyShell Attacks ❌

versions of the software are affected by a spate of bugs under active exploitations.

πŸ“– Read

via "Threat Post".
❌ Podcast: Ransomware Up x10: Disrupting Cybercrime Suppy Chains an Opportunity ❌

Derek Manky, Chief, Security Insights & Global Threat Alliances at Fortinet’s FortiGuard Labs, discusses the top threats and lessons learned from the first half of 2021.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep47: Daylight robbery, spaghetti trouble, and mousetastic superpowers [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-3734 β€Ό

yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27944 β€Ό

Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality, leading to OS command execution. The specific attack methodology is a file upload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38559 β€Ό

DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.

πŸ“– Read

via "National Vulnerability Database".
🦿 Tech companies pledge to help toughen US cybersecurity in White House meeting 🦿

Apple, Google, Microsoft and others will fund new technologies and training as part of the nation's struggle to combat cyberattacks.

πŸ“– Read

via "Tech Republic".
πŸ›  Wireshark Analyzer 3.4.8 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2021-36352 β€Ό

Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability has found POST requests in /modules/registration_admission/patient_register.php page with "name_middle", "addr_str", "station", "name_maiden", "name_2", "name_3" parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32076 β€Ό

Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the Ò€œWeb Help Desk Getting Started WizardҀ�, especially the admin account creationpage, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.

πŸ“– Read

via "National Vulnerability Database".
🦿 Google and mobile operating systems top list of privacy concerns, says Kaspersky 🦿

Using data gathered by its Privacy Checker website, Kaspersky has been able to pinpoint areas of concern for visitors seeking to improve their privacy posture.

πŸ“– Read

via "Tech Republic".
❌ F5 Bug Could Lead to Complete System Takeover ❌

The worst of 13 bugs fixed by the August updates could lead to complete system compromise for users in sensitive sectors running products in Appliance mode.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-40147 β€Ό

EmTec ZOC before 8.02.2 allows \e[201~ pastes, a different vulnerability than CVE-2021-32198.

πŸ“– Read

via "National Vulnerability Database".
🦿 How to create locally signed SSL certificates with mkcert 🦿

If you need to generate quick SSL certificates for test servers and services, mkcert might be the fastest option available. Jack Wallen shows you how to use this handy tool.

πŸ“– Read

via "Tech Republic".
πŸ” California Reminds Healthcare Orgs of Data Breach Reporting Obligations πŸ”

Hospitals and healthcare providers in the state have been failing to report ransomware attacks that impact health data belonging to patients.

πŸ“– Read

via "".
β€Ό CVE-2021-29487 β€Ό

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request. This only affects frontend users and the attacker must obtain a Laravel secret key for cookie encryption and signing in order to exploit this vulnerability. The issue has been patched in Build 472 and v1.1.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36929 β€Ό

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18476 β€Ό

SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18477 β€Ό

SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.

πŸ“– Read

via "National Vulnerability Database".