πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41503 β€Ό

** UNSUPPORTED WHEN ASSIGNED ** DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2016-6555 β€Ό

OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in version 18.0.2, released on September 20, 2016.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40655 β€Ό

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40654 β€Ό

An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2016-6556 β€Ό

OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent supplied data. By creating a malicious SNMP 'sysName' or 'sysContact' response, an attacker can store an XSS payload which will trigger when a user of the web UI views the data. This issue was fixed in version 18.0.2, released on September 20, 2016.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41504 β€Ό

** UNSUPPORTED WHEN ASSIGNED ** An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21742 β€Ό

There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Microsoft exposes BulletProofLink 'phishing as a service' criminal enterprise πŸ“’

The sophisticated outfit handles everything from template design to web hosting and credentials processing

πŸ“– Read

via "ITPro".
πŸ“’ The new frontier of endpoint management πŸ“’

How analytics and security stacks are driving employee experience initiatives

πŸ“– Read

via "ITPro".
πŸ“’ Critical flaw in vCenter Server could give hackers infrastructure access πŸ“’

VMware is urging users to patch the 9.8-rated vulnerability as soon as possible

πŸ“– Read

via "ITPro".
πŸ“’ New FamousSparrow hacking group caught targeting hotels πŸ“’

Microsoft Exchange ProxyLogon flaw used in attacks

πŸ“– Read

via "ITPro".
πŸ“’ Managing security and risk across the IT supply chain: A practical approach πŸ“’

Best practices for IT supply chain security

πŸ“– Read

via "ITPro".
πŸ“’ US Treasury sanctions crypto exchange over role in ransomware attacks πŸ“’

The Suex exchange allegedly facilitated financial transactions for ransomware actors

πŸ“– Read

via "ITPro".
πŸ“’ HP Wolf Security: Threat insights report πŸ“’

Equipping security teams with the knowledge to combat emerging threats

πŸ“– Read

via "ITPro".
πŸ“’ How to plan for endpoint security against ever-evolving cyber threats πŸ“’

Safeguard your devices, data, and reputation

πŸ“– Read

via "ITPro".
πŸ“’ Minnesota farm coop caught in ransomware attack πŸ“’

Crystal valley becomes second agribusiness to find data encrypted by criminals

πŸ“– Read

via "ITPro".
πŸ“’ LG continues automotive pivot with $240 million Cybellum acquisition πŸ“’

The Israeli startup detects vulnerabilities in automotive hardware and software services using digital twins

πŸ“– Read

via "ITPro".
πŸ“’ CISA, FBI, and NSA issue a Conti ransomware advisory πŸ“’

Joint statement with the FBI and the NSA warns of increased attacks from the Conti Ransomware

πŸ“– Read

via "ITPro".
πŸ“’ Phishing emails target victims with fake vaccine passport offer πŸ“’

Scammers could steal victims’ personal information and never deliver the illegal goods, Fortinet warns

πŸ“– Read

via "ITPro".
β€Ό CVE-2021-3830 β€Ό

btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".