πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Serious Security: Let’s Encrypt gets ready to go it alone (in a good way!) ⚠

Let's Encrypt is set to become a mainstream, self-certifying web certificate authority - here's why it took so many years.

πŸ“– Read

via "Naked Security".
🦿 3 tips to protect your users against credential phishing attacks 🦿

A new phishing campaign spotted by Armorblox tried to steal user credentials by spoofing a message notification from a company that provides email encryption.

πŸ“– Read

via "Tech Republic".
🦿 New Chrome feature can tell sites and webapps when you're idle 🦿

The new Idle Detection API gives Chrome the ability to register whether a user is active, and has drawn concerns from privacy advocates. Here's how to disable it.

πŸ“– Read

via "Tech Republic".
🦿 Deepwatch announces managed detection and response solution for SMBs 🦿

The fully-automated security operations center solution comes with 24/7 support and sets up in less than an hour.

πŸ“– Read

via "Tech Republic".
πŸ•΄ US Extradites CardPlanet Operator Back to Russia πŸ•΄

Russian national Aleksi Burkov was sentenced to nine years in prison for his operation of two websites facilitating payment card fraud.

πŸ“– Read

via "Dark Reading".
❌ SAS 2021: FinSpy Surveillance Kit Re-Emerges Stronger Than Ever ❌

A 'nearly impossible to analyze' version of the malware sports a bootkit and 'steal-everything' capabilities.

πŸ“– Read

via "Threat Post".
🦿 Don't let cybercriminals ruin your merger or acquisition 🦿

Companies are vulnerable to potential cyberthreats during mergers and acquisitions; learn from an expert why and how to reduce security risks during the transition.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-29361 β€Ό

A buffer overflow vulnerability in FORMATS!Read_Utah_RLE+0x340 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36366 β€Ό

Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29360 β€Ό

A buffer overflow vulnerability in FORMATS!Read_Utah_RLE+0x37a of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29362 β€Ό

A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa30 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29365 β€Ό

Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. This can cause a denial of service (DOS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36363 β€Ό

Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36364 β€Ό

Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29366 β€Ό

A buffer overflow vulnerability in FORMATS!GetPlugInInfo+0x2de9 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29358 β€Ό

A buffer overflow vulnerability in FORMATS!ReadPVR_W+0xfa of Irfanview 4.57 allows attackers to cause a denial of service (DOS) via a crafted PVR file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29363 β€Ό

A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa74 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.0xa74

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29364 β€Ό

A buffer overflow vulnerability in Formats!ReadRAS_W+0x1001 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41104 β€Ό

ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web_server` allows over-the-air (OTA) updates without checking user defined basic auth username & password. This issue is patched in version 2021.9.2. As a workaround, one may disable or remove `web_server`.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29367 β€Ό

A buffer overflow vulnerability in WPG+0x1dda of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted WPG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36365 β€Ό

Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

πŸ“– Read

via "National Vulnerability Database".