πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-3881 β€Ό

libmobi is vulnerable to Out-of-bounds Read

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40991 β€Ό

A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40989 β€Ό

A local escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 'Clumsy' BlackByte Malware Reuses Crypto Keys, Worms Into Networks πŸ•΄

Discovered during a recent incident response engagement, the malware avoids Russian computers and uses a single symmetric key for encrypting every compromised system.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep54: Another 0-day, double Apache patch, and Fight The Phish [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
⚠ LANtenna hack spies on your data from across the room! (Sort of) ⚠

Are your network cables acting as undercover wireless transmitters? What can you do if they are?

πŸ“– Read

via "Naked Security".
❌ Missouri Vows to Prosecute β€˜Hacker’ Who Disclosed Data Leak ❌

Missouri Gov. Mike Parson launched a criminal investigation of a reporter who flagged a state website that exposed 100K+ Social-Security numbers for teachers and other state employees.

πŸ“– Read

via "Threat Post".
🦿 Data center admins: Learn how to run a basic vulnerability scan on your Linux servers with Nessus 🦿

Make sure the Linux servers in your data center are free from vulnerabilities by scanning them immediately using Nessus.

πŸ“– Read

via "Tech Republic".
🦿 The White House holds an international summit on ransomware: What you should know 🦿

This week the White House held a summit with various nations to address the threat of ransomware. Learn some of the takeaways and why certain nations were excluded.

πŸ“– Read

via "Tech Republic".
πŸ•΄ How Attackers Hack Humans πŸ•΄

Inside their motivations, how they go about it -- and what businesses can do about it, according to Counterintelligence Institute founder Peter Warmka.

πŸ“– Read

via "Dark Reading".
❌ TrickBot Gang Enters Cybercrime Elite with Fresh Affiliates ❌

The group – which also created BazarLoader and the Conti ransomware – has juiced its distribution tactics to threaten enterprises more than ever.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-28021 β€Ό

Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29745 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29679 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41320 β€Ό

A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4951 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
🦿 How to use DocSecrets to encrypt sections of your Google Docs 🦿

If you need to hide sections of text in Google Documents, give the handy DocSecrets add-on a try.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-27561 β€Ό

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cisco Duo Trusted Access Report: More Than 50% of Companies Plan Passwordless Move πŸ•΄

Multifactor authentications soar as enterprises move away from passwords to secure hybrid workers.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2018-16060 β€Ό

Mitsubishi Electric SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-16061 β€Ό

Mitsubishi Electric SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.

πŸ“– Read

via "National Vulnerability Database".