πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38480 β€Ό

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the routerÒ€ℒs management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3851 β€Ό

firefly-iii is vulnerable to URL Redirection to Untrusted Site

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3872 β€Ό

vim is vulnerable to Heap-based Buffer Overflow

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38462 β€Ό

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and perform operations on their behalf.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38472 β€Ό

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTIONS header, which an attacker may take advantage of by sending a link to an administrator that frames the routerÒ€ℒs management portal and could lure the administrator to perform changes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3863 β€Ό

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38468 β€Ό

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to stored cross-scripting, which may allow an attacker to hijack sessions of users connected to the system.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ L0phtCrack password auditing tool goes open source πŸ—“οΈ

Original developers invite OS community to develop further capabilities

πŸ“– Read

via "The Daily Swig".
❌ A Guide to Doing Cyberintelligence on a Restricted Budget ❌

Cybersecurity budget cuts are everywhere. Chad Anderson, senior security researcher at DomainTools, discusses alternatives to fancy tooling, and good human skills alignment.

πŸ“– Read

via "Threat Post".
🦿 How to keep your data off the Dark Web 🦿

Traditional security solutions are no longer enough to protect your organization from a data breach, Bitglass says.

πŸ“– Read

via "Tech Republic".
🦿 Aruba introduces the industry's first distributed services switch 🦿

The new CX 10000 integrates security services, like a firewall, directly into a one-unit network switch deployable anywhere security and other services need to reside.

πŸ“– Read

via "Tech Republic".
🦿 How to proactively detect and prevent ransomware attacks 🦿

Two out of three organizations surveyed by ThycoticCentrify were hit by a ransomware attack over the past 12 months, and more than 80% reportedly opted to pay the ransom.

πŸ“– Read

via "Tech Republic".
🦿 Tech support scams top list of latest phishing threats 🦿

Tech support scams work because they try to trick people into believing there's a serious security crisis with their computers, says Norton Labs.

πŸ“– Read

via "Tech Republic".
⚠ Cybersecurity Awareness Month: Building your career ⚠

Explore. Experience. Share. How to get into cybersecurity...

πŸ“– Read

via "Naked Security".
πŸ—“οΈ (ISC)Β² hopes diversity drive will hasten glacial progress on plugging infosec workforce gap πŸ—“οΈ

CEO tells (ISC)Β² Security Congress how orgs should rethink hiring strategies

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Veritas Simplifies Data Backup to the Cloud While Helping Reduce Costs and Increase Ransomware Resiliency πŸ•΄

Introducing Veritas NetBackup Recovery Vault, a Veritas-managed cloud storage service.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Former NSA Deputy Director William Crowell Joins [redacted] Board of Directors πŸ•΄

Cybersecurity industry veteran brings substantial public and private sector experience to help guide [redacted] growth and expansion.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Data Privacy API Company Skyflow Raises $45M Series B Funding to Help Fintech and Healthtech Companies Ship Faster πŸ•΄

Achieves 8x growth in last three quarters, and raises $70M in less than 18 months.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-29622 β€Ό

A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-005 Catalina. Mounting a maliciously crafted NFS network share may lead to arbitrary code execution with system privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30847 β€Ό

This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30845 β€Ό

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6. A local user may be able to read kernel memory.

πŸ“– Read

via "National Vulnerability Database".