πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-20693 β€Ό

A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20691 β€Ό

An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.

πŸ“– Read

via "National Vulnerability Database".
❌ Credential Spear-Phishing Uses Spoofed Zix Encrypted Email ❌

The spoofed email has targeted close to 75K inboxes, slipping past spam and security controls across Office 365, Google Workspace, Exchange, Cisco ESA and more.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Better future? Safari browser extension is preparing for Apple’s β€˜post-privacy’ world πŸ—“οΈ

β€˜Apple’s plans to violate your privacy have left a sour taste in our mouths’, says developers

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-33600 β€Ό

A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the product.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36165 β€Ό

RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33601 β€Ό

A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server.

πŸ“– Read

via "National Vulnerability Database".
🦿 United Health Centers reportedly compromised by ransomware attack 🦿

A ransomware gang called Vice Society claims it grabbed confidential data such as patient benefits, financial documents and lab results.

πŸ“– Read

via "Tech Republic".
πŸ“’ 100 million IoT devices affected by zero-day flaw πŸ“’

Vulnerability could affect car, fire detection, and patient data sensors

πŸ“– Read

via "ITPro".
πŸ“’ What is a web filter? πŸ“’

We look at best ways to block, hide, or flag undesired search engine results

πŸ“– Read

via "ITPro".
πŸ“’ Malware developers create malformed code signatures to avoid detection πŸ“’

Google researchers uncovers technique used to push dodgy software onto unsuspecting victims

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft to scrap Basic Authentication in Exchange Online πŸ“’

The tech giant has announced October 2022 as the cut-off date for Exchange Online tenants

πŸ“– Read

via "ITPro".
πŸ—“οΈ Social media scam: Twitter bots are tricking users into making PayPal and Venmo payments into fraudsters’ accounts πŸ—“οΈ

Social engineering scammers are using cloned social media accounts to carry out deceit

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Modern Security Breaches Demand Diligent Planning and Executive Support πŸ•΄

Teams that remain reactive will always be on the back foot β€” take an active stance.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-37146 β€Ό

An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_comm via a crafted XMLRPC call.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41536 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13778).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41540 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13776).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41537 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13789).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41538 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to information disclosure by unexpected access to an uninitialized pointer while parsing user-supplied OBJ files. An attacker could leverage this vulnerability to leak information from unexpected memory locations (ZDI-CAN-13770).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41533 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process (ZDI-CAN-13565).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41535 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13771).

πŸ“– Read

via "National Vulnerability Database".