πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Contrast Application Security Platform Scales to Support OWASP Risks πŸ•΄

Contrast's platform detects and prevents against OWASP Top Ten risks from development to production with out-of-the-box policy rules and automated compliance reporting.

πŸ“– Read

via "Dark Reading".
🦿 10,000 employees at Stanley Black & Decker go passwordless 🦿

Here's how TruU's Passwordless Protection could make hybrid work easier and beef up security in the enterprise.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Meet TruffleHog – a browser extension for finding secret keys in JavaScript code πŸ—“οΈ

API keys are accidentally being leaked by websites. Here’s how to find them

πŸ“– Read

via "The Daily Swig".
⚠ S3 Ep51: OMIGOD a gaping hole, waybill scams, and Face ID hacked [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Developers fix multitude of vulnerabilities in Apache HTTP Server πŸ—“οΈ

High-impact SSRF and request smuggling bugs among flaws addressed in bumper patch cycle

πŸ“– Read

via "The Daily Swig".
❌ TangleBot Malware Reaches Deep into Android Device Functions ❌

The mobile baddie grants itself access to almost everything, enabling spying, data-harvesting, stalking and fraud attacks, among others.

πŸ“– Read

via "Threat Post".
🦿 iOS 15: How to enable Mail Privacy Protection 🦿

Learn how to use the new iOS 15 security feature called Mail Privacy Protection, which can hide your IP address and other tracking data often sent to marketers without your knowledge.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-41587 β€Ό

In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40099 β€Ό

An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41586 β€Ό

In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40102 β€Ό

An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40100 β€Ό

An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41588 β€Ό

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ TangleBot Campaign Underscores SMS Threat πŸ•΄

The attack targets Android devices and starts with a malicious SMS message that aims to bring malware onto compromised devices.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ” Friday Five 9/24 πŸ”

New iOS privacy settings, the Exchange autodiscover bug, and subsidiary risk - catch up on the week's infosec news with the Friday Five!

πŸ“– Read

via "".
β€Ό CVE-2021-28130 β€Ό

Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40309 β€Ό

A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own SQL query. The cp_id_miss_attn parameter from TakeAttendance.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request as a user with access to "Take Attendance" functionality to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40310 β€Ό

OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the cp_id_miss_attn parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords ❌

Hundreds of thousands of email credentials, many of which double as Active Directory domain credentials, came through to credential-trapping domains in clear text.

πŸ“– Read

via "Threat Post".
🦿 Are VPNs still the best solution for security? 🦿

Cybersecurity professionals rely on VPNs to secure remote endpoints with an organization's home network. One expert suggests there is a better, simpler and safer approach to accomplish the same thing.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Consumers Share Security Fears as Risky Behaviors Persist πŸ•΄

While most US adults know they aren't sufficiently protecting their data online, many find security time-consuming or don't know the steps they should take.

πŸ“– Read

via "Dark Reading".