๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.9K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2021-21570 โ€ผ

Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-36284 โ€ผ

Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive admin password attempt mitigations in order to carry out a brute force attack.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Outsourced Software Pose Greater Risks to Enterprise Application Security ๐Ÿ•ด

In the wake of SolarWinds and other third-party attacks, security teams worry that outsourced applications pose risks to the organization's application security, according to Dark Reading's recent "How Enterprises Are Developing Secure Applications" report.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด 75K Email Inboxes Hit in New Credential Phishing Campaign ๐Ÿ•ด

Attacker used a legitimate โ€” but likely deprecated โ€” domain to sneak malicious emails past security filters, vendor says.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2020-20122 โ€ผ

Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-20124 โ€ผ

Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-20120 โ€ผ

ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-20125 โ€ผ

EARCLINK ESPCMS-P8 contains a cross-site scripting (XSS) vulnerability in espcms_web\espcms_load.php.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ“ข What makes a password secure? ๐Ÿ“ข

IT security is constantly evolving to counter threats, but the password remains a key part of our security arsenal

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Amazon to offer cyber insurance to UK SMBs ๐Ÿ“ข

The insurance will cover risks such as accidental privacy breaches, extortion and ransomware

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Women and BAME individuals are hardest hit by cyber crime ๐Ÿ“ข

Malwarebytes calls on the technology industry to do more to provide secure internet access to everyone

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข UKโ€™s next National Cyber Strategy to reflect need for security industrial base ๐Ÿ“ข

The countryโ€™s upcoming National Cyber Security Strategy will 'hopefully' be released later this year

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Hackers spoof Zix in credential phishing attack ๐Ÿ“ข

The attack has impacted around 75,000 Office 365, Google Workspace and Exchange users

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Large companies fall short on domain security ๐Ÿ“ข

Most large businesses still need to implement enterprise-level controls

๐Ÿ“– Read

via "ITPro".
โ€ผ CVE-2021-32466 โ€ผ

An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-35028 โ€ผ

A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-36745 โ€ผ

A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-33923 โ€ผ

Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-33924 โ€ผ

Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-35027 โ€ผ

A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ™Ÿ๏ธ The Rise of One-Time Password Interception Bots โ™Ÿ๏ธ

In February, KrebsOnSecurity wrote about a novel cybercrime service that helped attackers intercept the one-time passwords (OTPs) that many websites require as a second authentication factor in addition to passwords. That service quickly went offline, but new research reveals a number of competitors have since launched bot-based services that make it relatively easy for crooks to phish OTPs from targets.

๐Ÿ“– Read

via "Krebs on Security".