πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-16630 β€Ό

TIÒ€ℒs BLE stack caches and reuses the LTKÒ€ℒs property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing to pair with a victim BLE device based on TI chips and generate an authenticated-and-MITM-protection LTK. If a fake mobile with the victim mobileÒ€ℒs MAC address uses Just Works and pairs with the victim device, the generated LTK still has the property of authenticated-and-MITM-protection. Therefore, the fake mobile can access attributes with the authenticated read/write permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39325 β€Ό

The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.6.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ US optometry provider Simon Eye hit by data breach impacting 144,000 patients πŸ—“οΈ

Compromise of employee mailboxes may have exposed sensitive medical data

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-26333 β€Ό

An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to the driver resulting in a potential data leak from uninitialized physical pages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31917 β€Ό

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20829 β€Ό

Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ French shipping giant CMA CGM suffers data breach πŸ—“οΈ

Customer data impacted by security incident

πŸ“– Read

via "The Daily Swig".
❌ BlackMatter Strikes Iowa Farmers Cooperative, Demands $5.9M Ransom ❌

Critical infrastructure appears to be targeted in latest ransomware attack, diminishing the hopes of governments to curb such attacks.

πŸ“– Read

via "Threat Post".
❌ 46% of On-Prem Databases Globally Contain Vulnerabilities: Is Yours Safe? ❌

Are organizations neglecting the security of their data? An unprecedented five-year study reveals that internal databases are riddled with vulnerabilities – some even years old.

πŸ“– Read

via "Threat Post".
🦿 U.S. companies excel at limiting shadow IT, according to a new report 🦿

Many respondents are planning to continue remote operations for the next couple of years, but what strategies are they implementing to protect themselves in the age of remote work at scale?

πŸ“– Read

via "Tech Republic".
🦿 How privacy and security challenges may cause people to abandon your website 🦿

More than half of consumers surveyed by Ping Identity said they ditched an online service when logging in proved too frustrating.

πŸ“– Read

via "Tech Republic".
🦿 Managing change in AI: Don't forget about your staff's needs and abilities 🦿

When change affects people in your organization, remember that you have a wealth of talent that needn't go to waste. Consider re-skilling to meet the company's needs as well as the employees'.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-37424 β€Ό

ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37419 β€Ό

ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37420 β€Ό

ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28960 β€Ό

ManageEngine Desktop Central before build 10.0.683 allows Unauthenticated Remote Code Execution during communication with Notification Server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37741 β€Ό

ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0869 β€Ό

In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-179620905 References: N/A

πŸ“– Read

via "National Vulnerability Database".
🦿 Google, Microsoft and Oracle amassed the most cybersecurity vulnerabilities in the first half of 2021 🦿

A recent AtlasVPN report rounds up an inglorious cybersecurity top 10 of sorts, highlighting the companies that have amassed the most vulnerabilities in the first half of this year.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Weaponized ManageEngine flaw poses β€˜serious risk’ to high-profile US targets – CISA πŸ—“οΈ

Warning from US government agency urges prompt triage

πŸ“– Read

via "The Daily Swig".
❌ Turla APT Plants Novel Backdoor In Wake of Afghan Unrest ❌

β€œTinyTurla,” simply coded malware that hides away as a legitimate Windows service, has flown under the radar for two years.

πŸ“– Read

via "Threat Post".