πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Security pre-advisories: A simple way to improve the patch management process πŸ—“οΈ

Improving enterprise security, one patch at a time

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Proposed HTTPA Protocol Uses TEEs to Secure the Web πŸ•΄

Intel researchers describe how Trusted Execution Environments can enhance HTTPS and boost web security.

πŸ“– Read

via "Dark Reading".
❌ Why is Cybersecurity Failing Against Ransomware? ❌

Hardly a week goes by without another major company falling victim to a ransomware attack. Nate Warfield, CTO at Prevailion, discusses the immense challenges in changing that status quo.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Bulletproof hosting duo jailed over support of cyber-attacks against US targets πŸ—“οΈ

Attacks leveraging defendants’ infrastructure inflicted heavy financial losses on victims

πŸ“– Read

via "The Daily Swig".
🦿 Microsoft bought CloudKnox because hybrid multicloud identity is complicated 🦿

Managing passwords and privileged access is bad enough for peopleβ€”but that's going to be dwarfed by the problem of dealing with non-human identities.

πŸ“– Read

via "Tech Republic".
πŸ•΄ How Psychology Can Save Your Cybersecurity Awareness Training Program πŸ•΄

Understanding human psychology, how it works, and how to introduce its concepts into cybersecurity awareness training can make a huge difference to your organization.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-35512 β€Ό

An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ New bug bounty platform launches for Indian ethical hackers πŸ—“οΈ

Security researchers can sign up now

πŸ“– Read

via "The Daily Swig".
🦿 How to digitally sign email in Apple Mail 🦿

Adding a digital signature to your email is just one simple step you can take in your journey for more secure communications. Jack Wallen shows you how this is done in the latest version of Apple Mail.

πŸ“– Read

via "Tech Republic".
πŸ›  AntiRansom 5 πŸ› 

AntiRansom is a tool capable of detecting and mitigating attacks of Ransomware using honeypots.

πŸ“– Read

via "Packet Storm Security".
⚠ S3 Ep55: Live malware, global encryption, dating scams, and secret emanations [Podcasts] ⚠

Latest episode - listen now! (And sign up for our forthcoming Live Malware Demo at the same time.)

πŸ“– Read

via "Naked Security".
πŸ•΄ Macs Still Targeted Mostly With Adware, Less With Malware πŸ•΄

The top 10 categories of digital threats on macOS are all adware programs, with only a sliver of the share of victims affected by actual malware, according to an IT management firm.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42740 β€Ό

The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with exec(), an attacker can inject arbitrary commands. This is because the Windows drive letter regex character class is {A-z] instead of the correct {A-Za-z]. Several shell metacharacters exist in the space between capital letter Z and lower case letter a, such as the backtick character.

πŸ“– Read

via "National Vulnerability Database".
❌ Gigabyte Allegedly Hit by AvosLocker Ransomware ❌

If AvosLocker stole Gigabyte's master keys, threat actors could force hardware to download fake drivers or BIOS updates in a supply-chain attack a la SolarWinds.

πŸ“– Read

via "Threat Post".
πŸ•΄ Microsoft Launches Security Program for Nonprofits πŸ•΄

A new set of security tools is built to assess risk, provide monitoring and notification if an attack occurs, and train IT pros and users.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-28975 β€Ό

WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted server_host, server_name, or connection_parameter parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20120 β€Ό

The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29883 β€Ό

IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 207090.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27304 β€Ό

The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14263 β€Ό

"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29873 β€Ό

IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.

πŸ“– Read

via "National Vulnerability Database".