πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-30632 β€Ό

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42112 β€Ό

The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30625 β€Ό

Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30626 β€Ό

Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30627 β€Ό

Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30629 β€Ό

Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-22617 β€Ό

Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30630 β€Ό

Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30628 β€Ό

Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30633 β€Ό

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ The IT Pro Podcast: Behind the scenes of the Solarwinds hack πŸ“’

We speak to the company’s top execs to find out what really happened

πŸ“– Read

via "ITPro".
πŸ“’ Maverick fast-attack ransomware group FIN12 is quickly expanding πŸ“’

FIN12 hits hospitals even during pandemic

πŸ“– Read

via "ITPro".
πŸ“’ What is NotPetya? πŸ“’

We take a look at the malware that first came to prominence in 2016 and targets Windows-based machines

πŸ“– Read

via "ITPro".
πŸ“’ 2021 Thales access management index: Global edition πŸ“’

The challenges of trusted access in a cloud-first world

πŸ“– Read

via "ITPro".
πŸ“’ Twitch confirms data breach after server configuration error πŸ“’

The popular streaming service says there's no indication that login information has been exposed

πŸ“– Read

via "ITPro".
πŸ“’ Why is the energy sector so vulnerable to hacking? πŸ“’

Highly-targeted energy companies often struggle to attract the right cyber security skills and rely on dated systems

πŸ“– Read

via "ITPro".
πŸ“’ SolarWinds hackers stole US sanctions policy data, Microsoft confirms πŸ“’

Unconfirmed reports also suggest data on threat hunting techniques, assessments of Russian threat actors, and source codes were also accessed

πŸ“– Read

via "ITPro".
πŸ“’ Google will auto-enrol 150 million users in 2FA by end of 2021 πŸ“’

An additional two million YouTube creators will also be required to switch it on the 2SV feature by the end of the year

πŸ“– Read

via "ITPro".
πŸ“’ How to become a cyber security expert πŸ“’

With cyber security professionals in high demand, we explore the steps people need to take to pursue a successful career in this industry

πŸ“– Read

via "ITPro".
πŸ“’ The event mesh: A primer πŸ“’

Benefits of an event-driven architecture

πŸ“– Read

via "ITPro".
πŸ“’ Best free malware removal tools 2021 πŸ“’

Worried your device is infected? Here are the tools you need to get rid of malicious software

πŸ“– Read

via "ITPro".