πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-36165 β€Ό

RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33601 β€Ό

A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server.

πŸ“– Read

via "National Vulnerability Database".
🦿 United Health Centers reportedly compromised by ransomware attack 🦿

A ransomware gang called Vice Society claims it grabbed confidential data such as patient benefits, financial documents and lab results.

πŸ“– Read

via "Tech Republic".
πŸ“’ 100 million IoT devices affected by zero-day flaw πŸ“’

Vulnerability could affect car, fire detection, and patient data sensors

πŸ“– Read

via "ITPro".
πŸ“’ What is a web filter? πŸ“’

We look at best ways to block, hide, or flag undesired search engine results

πŸ“– Read

via "ITPro".
πŸ“’ Malware developers create malformed code signatures to avoid detection πŸ“’

Google researchers uncovers technique used to push dodgy software onto unsuspecting victims

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft to scrap Basic Authentication in Exchange Online πŸ“’

The tech giant has announced October 2022 as the cut-off date for Exchange Online tenants

πŸ“– Read

via "ITPro".
πŸ—“οΈ Social media scam: Twitter bots are tricking users into making PayPal and Venmo payments into fraudsters’ accounts πŸ—“οΈ

Social engineering scammers are using cloned social media accounts to carry out deceit

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Modern Security Breaches Demand Diligent Planning and Executive Support πŸ•΄

Teams that remain reactive will always be on the back foot β€” take an active stance.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-37146 β€Ό

An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_comm via a crafted XMLRPC call.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41536 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13778).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41540 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13776).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41537 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13789).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41538 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to information disclosure by unexpected access to an uninitialized pointer while parsing user-supplied OBJ files. An attacker could leverage this vulnerability to leak information from unexpected memory locations (ZDI-CAN-13770).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41533 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process (ZDI-CAN-13565).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41535 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13771).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41534 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process (ZDI-CAN-13703).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41539 β€Ό

A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13773).

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Mission accomplished: Security plugin HTTPS Everywhere to be deprecated in 2022 πŸ—“οΈ

Browser extension can be retired as push to encrypt the web is almost complete, says EFF

πŸ“– Read

via "The Daily Swig".
❌ SolarWinds Attackers Hit Active Directory Servers with FoggyWeb Backdoor ❌

Microsoft is warning that the Nobelium APT is compromising single-sign-on servers to install a post-exploitation backdoor that steals data and maintains network persistence.

πŸ“– Read

via "Threat Post".
❌ Working Exploit Is Out for VMware vCenter CVE-2021-22005 Flaw ❌

The unredacted RCE exploit allows unauthenticated, remote attackers to upload files to the vCenter Server analytics service.

πŸ“– Read

via "Threat Post".