πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-23029 β€Ό

On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23026 β€Ό

BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Apple patches zero-day flaw abused by infamous NSO exploit πŸ“’

The ForcedEntry flaw affects all Apple devices and allows hackers to compromise systems without any user interaction

πŸ“– Read

via "ITPro".
πŸ“’ WhatsApp activates end-to-end encrypted cloud backups πŸ“’

The messaging service will grant users a password-protected key when they save their chat histories to the cloud

πŸ“– Read

via "ITPro".
πŸ“’ Dual citizen sentenced to 11 years for role in North Korean crypto hacking scheme πŸ“’

Ontario resident laundered cash for North Korea from bank heists and BEC scams

πŸ“– Read

via "ITPro".
πŸ“’ Olympus hit by suspected ransomware attack πŸ“’

The former digital camera specialist has shut down its networks in Europe, Africa and the Middle East while it investigates the incident

πŸ“– Read

via "ITPro".
πŸ“’ Irish data regulator fails to resolve 98% of big tech GDPR cases πŸ“’

Campaigners accuse the Irish DPC of being the β€˜bottleneck’ for GDPR enforcement with 160 unresolved complaints

πŸ“– Read

via "ITPro".
πŸ“’ Google handed user data to Hong Kong authorities despite pledge πŸ“’

The tech giant last year said it would suspend the processing of user data requests from the Hong Kong government after a law that criminalised protests was introduced

πŸ“– Read

via "ITPro".
πŸ“’ Medigate and CrowdStrike bolster IoT medical device security πŸ“’

CrowdStrike will integrate its Falcon software with Medigate’s device security platform

πŸ“– Read

via "ITPro".
πŸ“’ Hackers develop Linux port of Cobalt Strike for new attacks πŸ“’

The modified version of the penetration testing toolkit can evade malware detection

πŸ“– Read

via "ITPro".
πŸ“’ BT conducts 'world's first' trial of quantum-secure communications πŸ“’

The achievement was made possible using hollow-core fibre cable provided by a Southampton Uni startup

πŸ“– Read

via "ITPro".
πŸ“’ Robust password policies cut cyber attacks by 60% πŸ“’

Research shows that hackers most often use brute force password attacks and flaw exploitation

πŸ“– Read

via "ITPro".
πŸ“’ The most secure email services of 2021 πŸ“’

Email is not secure by design, but these email providers allow you to send emails with top-level security

πŸ“– Read

via "ITPro".
πŸ“’ Smishing attacks increased 700% in first six months of 2021 πŸ“’

Which? has urged businesses to play their part to protect people from text message scams

πŸ“– Read

via "ITPro".
πŸ“’ IoT devices are more vulnerable than ever πŸ“’

Ove a billion attacks recorded on IoT devices in the first six months of the year

πŸ“– Read

via "ITPro".
πŸ—“οΈ Credential leak fears raised following security breach at Travis CI πŸ—“οΈ

DevOps firm slammed for β€˜abysmal’ incident response

πŸ“– Read

via "The Daily Swig".
❌ Attackers Impersonate DoT in Two-Day Phishing Scam ❌

Threat actors dangled the lure of receiving funds from the $1 trillion infrastructure bill and created new domains mimicking the real federal site.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Supply chain attacks against the open source ecosystem soar by 650% – report πŸ—“οΈ

Dependency confusion has quickly become the attack technique of choice

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-38656 β€Ό

Microsoft Word Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38647 β€Ό

Open Management Infrastructure Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36965 β€Ό

Windows WLAN AutoConfig Service Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".