πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-21604 β€Ό

libde265 v1.0.4 contains a heap buffer overflow fault in the _mm_loadl_epi64 function, which can be exploited via a crafted a file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3812 β€Ό

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41303 β€Ό

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3807 β€Ό

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-1947 β€Ό

Use-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3804 β€Ό

taro is vulnerable to Inefficient Regular Expression Complexity

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30260 β€Ό

Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-1939 β€Ό

Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-1976 β€Ό

A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3811 β€Ό

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3805 β€Ό

object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3810 β€Ό

code-server is vulnerable to Inefficient Regular Expression Complexity

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30261 β€Ό

Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3803 β€Ό

nth-check is vulnerable to Inefficient Regular Expression Complexity

πŸ“– Read

via "National Vulnerability Database".
❌ AT&T Phone-Unlocking Malware Ring Costs Carrier $200M ❌

With the help of malicious insiders, a fraudster was able to install malware and remotely divorce iPhones and other handsets from the carrier's U.S. network -- all the way from Pakistan.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Google announces partnership to review security of open source software projects πŸ—“οΈ

Tech giant will lend its support to security reviews of eight projects, including Git, Lodash, and Laravel 

πŸ“– Read

via "The Daily Swig".
❌ Ditch the Alert Cannon: Modernizing IDS is a Security Must-Do ❌

Jeff Costlow, CISO at ExtraHop, makes the case for implementing next-gen intrusion-detection systems (NG-IDS) and retiring those noisy 90s compliance platforms.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Epik hack exposes lax security practices at controversial web host πŸ—“οΈ

ISP guilty of β€˜laziest design possible’, critics allege

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Alaska Department of Health reveals data breach potentially exposing residents’ financial, health information πŸ—“οΈ

Disclosure part of lengthy investigation into sophisticated attack that took place in May

πŸ“– Read

via "The Daily Swig".
🦿 Small businesses need to step up efforts to secure and retain hybrid workers 🦿

Only 31% are shipping laptops to employees and nearly half have spent their own money on a remote workspace, a survey from GetApp finds.

πŸ“– Read

via "Tech Republic".
🦿 Dell study finds most organizations don't think they can recover from a ransomware attack 🦿

Sixty-seven percent lack confidence in their ability to recover business-critical data, which is troubling given that the amount of data businesses manage has grown by more than 10x since 2016.

πŸ“– Read

via "Tech Republic".
πŸ‘1