πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ›  Zeek 4.0.4 πŸ› 

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. While focusing on network security monitoring, Zeek provides a comprehensive platform for more general network traffic analysis as well. Well grounded in more than 15 years of research, Zeek has successfully bridged the traditional gap between academia and operations since its inception. Today, it is relied upon operationally in particular by many scientific environments for securing their cyber-infrastructure. Zeek's user community includes major universities, research labs, supercomputing centers, and open-science communities. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
🦿 How phishing-as-a-service operations pose a threat to organizations 🦿

Attackers can easily buy, deploy and scale phishing campaigns to steal credentials and other sensitive data, says Microsoft.

πŸ“– Read

via "Tech Republic".
🦿 Ransomware detections dropped by almost half, but the threat is only getting worse, says Trend Micro 🦿

Rather than indicating ransomware was a passing fad, the decrease in attack volume shows that attackers are starting to become more opportunistic and smarter about picking targets.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-32963 β€Ό

Null pointer dereference in SuiteLink server while processing commands 0x03/0x10

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32959 β€Ό

Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32979 β€Ό

Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41381 β€Ό

Payara Micro Community 5.2021.6 and below allows Directory Traversal.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26750 β€Ό

DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via maliciously crafted DLL file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32999 β€Ό

Improper handling of exceptional conditions in SuiteLink server while processing command 0x01

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41428 β€Ό

Insecure permissions in Update Manager <= 5.8.0.2300 and DFL <= 12.5.1001.5 in DATEV programs v14.1 allows attacker to escalate privileges via insufficient configuration of service components.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21913 β€Ό

An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can connect to the MQTT service to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32987 β€Ό

Null pointer dereference in SuiteLink server while processing command 0x0b

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36872 β€Ό

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32971 β€Ό

Null pointer dereference in SuiteLink server while processing command 0x07

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3824 β€Ό

OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.

πŸ“– Read

via "National Vulnerability Database".
⚠ How Outlook β€œautodiscover” could leak your passwords – and how to stop it ⚠

The Microsoft Autodiscover "Great Leak" explained - and how to prevent it

πŸ“– Read

via "Naked Security".
⚠ VMware patch bulletin warns: β€œThis needs your immediate attention.” ⚠

"It is a matter of time before working exploits are available," warns VMware.

πŸ“– Read

via "Naked Security".
🦿 How phishing-as-a-service operations pose a threat to organizations 🦿

Attackers can easily buy, deploy and scale phishing campaigns to steal credentials and other sensitive data, says Microsoft.

πŸ“– Read

via "Tech Republic".
🦿 Breached passwords: Popular TV shows don't make for the best security credentials 🦿

Specops recently released a roundup of the top 20 TV shows found on breached password lists. These shows offer plenty of entertainment, but aren't ideal for password inspiration. Sorry, "Cheers" fans.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-4941 β€Ό

IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22276 β€Ό

The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.

πŸ“– Read

via "National Vulnerability Database".