๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ“ข How to become a cyber security expert ๐Ÿ“ข

With cyber security professionals in high demand, we explore the steps people need to take to pursue a successful career in this industry

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข The event mesh: A primer ๐Ÿ“ข

Benefits of an event-driven architecture

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Best free malware removal tools 2021 ๐Ÿ“ข

Worried your device is infected? Here are the tools you need to get rid of malicious software

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Senator to introduce new bill to force ransomware payment disclosures ๐Ÿ“ข

Organizations would have 48 hours to inform DHS

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Swimlane unveils its low-code security automation platform ๐Ÿ“ข

Swimlane Cloud is available as an on-premises, air-gapped, cloud, or hybrid solution

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Identity Automation launches credential breach monitoring service ๐Ÿ“ข

New monitoring solution adds to the firmโ€™s flagship RapidIdentity platform

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข What is HTTP error 503 and how do you fix it? ๐Ÿ“ข

It may not always be obvious what's causing the issue, but there are steps you can take to get back online

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข BrewDog app flaw exposed data on 200,000 shareholders and customers, researchers claim ๐Ÿ“ข

Researchers at Pen Test Partners say API token exploit could have allowed hackers to access personal information and account details

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Only a third of businesses have taken out insurance against ransomware attacks ๐Ÿ“ข

Almost one in six also reported having no disaster recovery plan in place

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Justice Department unveils civil cyber fraud initiative to battle online crime ๐Ÿ“ข

New proposal will respond to cyber security breaches and cryptocurrency use in undertaking cyber fraud

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข 2021 Thales access management index: European edition ๐Ÿ“ข

The challenges of trusted access in a cloud-first world

๐Ÿ“– Read

via "ITPro".
โ€ผ CVE-2021-42135 โ€ผ

HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42134 โ€ผ

The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-41055 โ€ผ

Gajim 1.2.x and 1.3.x before 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID equals the correction ID.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24563 โ€ผ

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24719 โ€ผ

The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24681 โ€ผ

The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24576 โ€ผ

The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-40889 โ€ผ

CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents() function to write username in password.php file when a user successfully changed their password. The attacker can inject malicious PHP code into password.php and then use the login function to execute code.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-40884 โ€ผ

Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24737 โ€ผ

The Comments รƒยขรขโ€šยฌรขโ‚ฌล“ wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

๐Ÿ“– Read

via "National Vulnerability Database".