πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 10 Recent Examples of How Insider Threats Can Cause Big Breaches and Damage πŸ•΄

Theft of intellectual property, sabotage, exposure of sensitive data and more were caused by malicious behavior and negligence at these organizations

πŸ“– Read

via "Dark Reading".
πŸ•΄ Akamai Acquires Guardicore in $600M Deal πŸ•΄

In other acquisition news today, Arctic Wolf announced it will acquire Habitu8, a managed security awareness platform, for an undisclosed amount.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-20746 β€Ό

A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41324 β€Ό

Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cells files belonging to any user) via the nodes parameter (for Copy and Move) or via the Path parameter (for Delete).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33583 β€Ό

REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41101 β€Ό

wire-server is an open-source back end for Wire, a secure collaboration platform. Before version 2.106.0, the CORS ` Access-Control-Allow-Origin ` header set by `nginz` is set for all subdomains of `.wire.com` (including `wire.com`). This means that if somebody were to find an XSS vector in any of the subdomains, they could use it to talk to the Wire API using the user's Cookie. A patch does not exist, but a workaround does. To make sure that a compromise of one subdomain does not yield access to the cookie of another, one may limit the `Access-Control-Allow-Origin` header to apps that actually require the cookie (account-pages, team-settings and the webapp).

πŸ“– Read

via "National Vulnerability Database".
❌ Google Emergency Update Fixes Two Chrome Zero Days ❌

This is the second pair of zero days that Google's fixed this month, all four of which have been actively exploited in the wild.

πŸ“– Read

via "Threat Post".
πŸ•΄ More Than 90% of Q2 Malware Was Hidden in Encrypted Traffic πŸ•΄

Analysis of threat trends from last quarter reveals attackers ramped up their use of fileless malware, and zero-day malware accounted for almost two-thirds of all detections.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-20796 β€Ό

FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20799 β€Ό

JeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the commentText parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20797 β€Ό

FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ US retailer Neiman Marcus notifies 4.6 million customers of data breach πŸ—“οΈ

Department store chain forces password reset after discovering 2020 incident last month

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-23893 β€Ό

Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Cloudflare enters the email security business πŸ“’

New email routing and DNS Wizard capabilities make email management a breeze

πŸ“– Read

via "ITPro".
πŸ“’ Android Trojan charges millions of victims €36 per month πŸ“’

Up to 10 million users across 70 countries are thought to have been affected

πŸ“– Read

via "ITPro".
πŸ“’ Account takeovers rise nearly threefold during pandemic πŸ“’

Financial services hit hardest by account hijackers, says Sift report

πŸ“– Read

via "ITPro".
πŸ“’ The worst hacks of all time πŸ“’

Yahoo, LinkedIn, Facebook, here is a quick guide to some of the biggest data breaches in history

πŸ“– Read

via "ITPro".
πŸ“’ Akamai to acquire cyber security firm Guardicore πŸ“’

Guardicore’s micro-segmentation solution will add to Akamai’s Zero Trust Security portfolio

πŸ“– Read

via "ITPro".
πŸ“’ Detained Russian cyber sec tycoon 'exposed classified data', state media claims πŸ“’

Ilya Sachkov is accused of handing over security data to foreign intelligence services

πŸ“– Read

via "ITPro".
πŸ“’ NSA and CISA offer new security guidance for VPNs πŸ“’

Multiple nation-state threat actors using known flaws to access systems

πŸ“– Read

via "ITPro".
πŸ“’ Cellebrite launches industry-first remote data collection solution πŸ“’

New solution aids organizations’ e-discovery and corporate investigation procedures

πŸ“– Read

via "ITPro".