πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” CISA Rolls Out New Insider Threat Risk Assessment Tool πŸ”

The tool, which is intended for both public and private sector organizations, can help companies better assess their vulnerability to insider threats.

πŸ“– Read

via "".
🦿 Dell announces new ProSupport Suite and AI-powered Trusted Device capabilities 🦿

Both could help businesses struggling to secure remote workforces and protect ever-increasing vulnerability footprints.

πŸ“– Read

via "Tech Republic".
🦿 Windows Server 2022: A cheat sheet 🦿

Microsoft has just released its most recent Windows Server platform. Check out the improved hybrid cloud features, beefed up security and improved support for large on-premises applications.

πŸ“– Read

via "Tech Republic".
❌ Military’s RFID Tracking of Guns May Endanger Troops ❌

RFID gun tags leave the military exposed to tracking, sniffing and spoofing attacks, experts say.  

πŸ“– Read

via "Threat Post".
🦿 How to install the Nessus vulnerability scanner on Rocky Linux 🦿

If you're looking for one of the best vulnerability scanners on the market, Nessus might be the ticket. Jack Wallen shows you how to install this platform on Rocky Linux.

πŸ“– Read

via "Tech Republic".
πŸ•΄ FireEye Products & McAfee Enterprise Merge to Create $2B Entity πŸ•΄

The combined company will have 5,000 employees, more than 40,000 customers, and nearly $2 billion in revenue, officials report.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-41323 β€Ό

Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belonging to any user, via the format parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35198 β€Ό

NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stored Cross-Site Scripting (XSS) in the Packet Analysis module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35200 β€Ό

NETSCOUT nGeniusONE 6.3.0 build 1196 allows high-privileged users to achieve Stored Cross-Site Scripting (XSS) in FDSQueryService.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35199 β€Ό

NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35205 β€Ό

NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35201 β€Ό

NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35202 β€Ό

NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41325 β€Ό

Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In addition, such users can be granted several admin permissions via the Roles parameter.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35204 β€Ό

NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Reflected Cross-Site Scripting (XSS) in the support endpoint.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41288 β€Ό

Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35203 β€Ό

NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 10 Recent Examples of How Insider Threats Can Cause Big Breaches and Damage πŸ•΄

Theft of intellectual property, sabotage, exposure of sensitive data and more were caused by malicious behavior and negligence at these organizations

πŸ“– Read

via "Dark Reading".
πŸ•΄ Akamai Acquires Guardicore in $600M Deal πŸ•΄

In other acquisition news today, Arctic Wolf announced it will acquire Habitu8, a managed security awareness platform, for an undisclosed amount.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-20746 β€Ό

A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41324 β€Ό

Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cells files belonging to any user) via the nodes parameter (for Copy and Move) or via the Path parameter (for Delete).

πŸ“– Read

via "National Vulnerability Database".