πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41335 β€Ό

Windows Kernel Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40467 β€Ό

Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-40443, CVE-2021-40466.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41338 β€Ό

Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34453 β€Ό

Microsoft Exchange Server Denial of Service Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41355 β€Ό

.NET Core and Visual Studio Information Disclosure Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41330 β€Ό

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41331 β€Ό

Windows Media Audio Decoder Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41353 β€Ό

Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40487 β€Ό

Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41344.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41347 β€Ό

Windows AppX Deployment Service Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40484 β€Ό

Microsoft SharePoint Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-40483.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Firefox Suggest lands in the US, bringing ads to the browser search bar πŸ—“οΈ

New feature has been rolled out to a select group of users in the US

πŸ“– Read

via "The Daily Swig".
❌ 30 Mins or Less: Rapid Attacks Extort Orgs Without Ransomware ❌

The previously unknown SnapMC group exploits unpatched VPNs and webserver apps to breach systems and carry out quick-hit extortion in less time than it takes to order a pizza.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-33609 β€Ό

Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.

πŸ“– Read

via "National Vulnerability Database".
❌ OpenSea β€˜Free Gift’ NFTs Drain Cryptowallet Balances ❌

Cybercriminals exploited bugs in the world's largest digital-goods marketplace to create malicious artwork offered as a perk to unsuspecting users.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Nagios XI updated to address trio of security vulnerabilities πŸ—“οΈ

Post-auth flaws could give attackers a platform from which to pivot to other parts of the network

πŸ“– Read

via "The Daily Swig".
❌ Mandating a Zero-Trust Approach for Software Supply Chains ❌

Sounil Yu, CISO at JupiterOne, discusses software bills of materials (SBOMs) and the need for a shift in thinking about securing software supply chains.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ β€˜Find out what sparks joy’ – YouTube educator and security expert Katie Paxton-Fear on carving out a successful infosec career πŸ—“οΈ

β€˜Never stop learning’, Swig readers told during Q&A session

πŸ“– Read

via "The Daily Swig".
πŸ•΄ A Close Look at Russia's Ghostwriter Campaign πŸ•΄

The group, which conducts espionage and sows disinformation, is larger than previously thought and has shifted tactics.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ How Coinbase Phishers Steal One-Time Passwords β™ŸοΈ

A recent phishing campaign targeting Coinbase users shows thieves are getting cleverer about phishing one-time passwords (OTPs) needed to complete the login process. It also shows that phishers are attempting to sign up for new Coinbase accounts by the millions as part of an effort to identify email addresses that are already associated with active accounts.

πŸ“– Read

via "Krebs on Security".
🦿 Securing Microsoft 365 with app governance 🦿

How can you protect your network and data from consent phishing attacks? Microsoft's new app compliance program can help.

πŸ“– Read

via "Tech Republic".