πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-24677 β€Ό

The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24735 β€Ό

The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24516 β€Ό

The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes, allowing high privilege users such as admin to set XSS payload in it, even when the unfiltered_html is disallowed, leading to an Authenticated Stored Cross-Site Scripting issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24622 β€Ό

The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41971 β€Ό

Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ US links $5.2 billion in Bitcoin transactions to ransomware πŸ“’

A new report from the Treasury ties the cryptocurrency to ransomware payments over a ten year period

πŸ“– Read

via "ITPro".
πŸ“’ Acer Taiwan falls victim to cyber attack πŸ“’

Hackers obtained employee data three days after they breached Acer India servers

πŸ“– Read

via "ITPro".
πŸ“’ The rise of cloud misconfiguration threats and how to avoid them πŸ“’

Businesses must adopt new tools and practices to combat one of the leading causes of security breaches

πŸ“– Read

via "ITPro".
πŸ“’ Marsh McLennan reveals its cyber risk analytics center πŸ“’

The center combines the expertise of Marsh, Guy Carpenter, Mercer, and Oliver Wyman

πŸ“– Read

via "ITPro".
🦿 Is your organization safe from a cybersecurity attack? 🦿

How is your company preventing the terror of a potential cybersecurity breach? Take this quick, multiple choice survey and tell us about it.

πŸ“– Read

via "Tech Republic".
❌ TikTok Serves Up Fresh Gamer Targets via Fake Among Us, Steam Offerings ❌

The tween-friendly video app is being used to serve up malvertising, disguised as free Steam game accounts or Among Us game hacks.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-36513 β€Ό

An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42055 β€Ό

ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23449 β€Ό

This affects the package vm2 before 3.9.4. Prototype Pollution attack vector can lead to sandbox escape and execution of arbitrary code on the host machine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29878 β€Ό

IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 206581.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Sinclair Broadcast Group Confirms Ransomware Attack πŸ•΄

The US television station operator has revealed certain servers and workstations, as well as office and operational networks, were disrupted in the attack.

πŸ“– Read

via "Dark Reading".
πŸ” DOJ Aims to Keep Companies Accountable with Cyber-Fraud Initiative πŸ”

Companies that fail to follow required cybersecurity standards could soon be a target under the DOJ's new Civil Cyber-Fraud Initiative.

πŸ“– Read

via "".
πŸ•΄ NSA, FBI, CISA Issue Advisory on 'BlackMatter' Ransomware πŸ•΄

Ransomware has become a "national security issue," NSA director said.

πŸ“– Read

via "Dark Reading".
❌ Sinclair Confirms Ransomware Attack That Disrupted TV Stations ❌

A major cyberattack resulted in data being stolen, too, but Sinclair's not sure which information is now in the hands of the crooks.

πŸ“– Read

via "Threat Post".
🦿 Gartner analyst: 12 technologies to accelerate growth, engineer trust and sculpt change in 2022 🦿

CIOs must prioritize the same business imperatives and find the IT force multipliers to enable growth and innovation, according to a Gartner analyst during Gartner's IT Symposium.

πŸ“– Read

via "Tech Republic".
❌ Podcast: Could the Zoho Flaw Trigger SolarWinds 2.0? ❌

Companies are worried that the highly privileged password app could let attackers deep inside an enterprise’s footprint, says Redscan’s George Glass.

πŸ“– Read

via "Threat Post".