🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🦿 How to encrypt specific sections of Google Docs with the DocSecrets add-on 🦿

Anyone who needs to hide away sections of text in Google Documents should give this handy add-on a try.

📖 Read

via "Tech Republic".
Europol announces two more ransomware busts in Ukraine

"Two in custody," as they say. Cars, cash and cryptocoins nabbed as well.

📖 Read

via "Naked Security".
Apache web server zero-day bug is easy to exploit – patch now!

Some of us have Apache as our primary web server. But lots of us may have Apache without knowing it, as part of another product.

📖 Read

via "Naked Security".
🕴 Why Not Sharing Is Caring When It Comes to Cybersecurity 🕴

Three key tips to help ensure your employees keep vital information safe.

📖 Read

via "Dark Reading".
🕴 Amazon's Twitch Streaming Service Hacked, Sensitive Data Leaked 🕴

Attackers claim to have dumped Twitch source code, payment information, and unreleased gaming product plan online.

📖 Read

via "Dark Reading".
ESPecter Bootkit Malware Haunts Victims with Persistent Espionage

The rare UEFI bootkit drops a fully featured backdoor on PCs and gains the ultimate persistence by modifying the Windows Boot Manager.

📖 Read

via "Threat Post".
CVE-2021-29760

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unauthorized files through the dashboard user interface. IBM X-Force ID: 202213.

📖 Read

via "National Vulnerability Database".
CVE-2021-29855

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205684.

📖 Read

via "National Vulnerability Database".
CVE-2021-20264

An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

📖 Read

via "National Vulnerability Database".
CVE-2021-29761

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information from the dashboard that they should not have access to. IBM X-Force ID: 202265.

📖 Read

via "National Vulnerability Database".
CVE-2021-29798

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734.

📖 Read

via "National Vulnerability Database".
CVE-2021-38925

IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171.

📖 Read

via "National Vulnerability Database".
CVE-2021-29764

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 202268.

📖 Read

via "National Vulnerability Database".
CVE-2021-39350

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

📖 Read

via "National Vulnerability Database".
CVE-2021-29758

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X-Force ID: 202169.

📖 Read

via "National Vulnerability Database".
CVE-2021-29836

IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204912.

📖 Read

via "National Vulnerability Database".
CVE-2021-29837

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204913.

📖 Read

via "National Vulnerability Database".
CVE-2021-29903

IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 207506.

📖 Read

via "National Vulnerability Database".
CVE-2021-39351

The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2.

📖 Read

via "National Vulnerability Database".
🦿 Over 1.5 billion Facebook users' personal data found for sale on hacker forum 🦿

Unrelated to other recent problems Facebook has had, this particular batch of data was scraped from profiles, meaning it's publicly available knowledge. That doesn't stop it from being dangerous.

📖 Read

via "Tech Republic".
🔏 New Ransomware Bill Would Require Organizations Report Ransom Costs 🔏

A bill introduced this week would require companies to disclose ransomware attacks and how much they cost victims within 48 hours.

📖 Read

via "".