πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ North Korea's Lazarus Group Turns to Supply Chain Attacks πŸ•΄

State-backed group is among a growing number of threat actors looking at supply chain companies as an entry point into enterprise networks.

πŸ“– Read

via "Dark Reading".
❌ SquirrelWaffle Loader Malspams, Packing Qakbot, Cobalt Strike ❌

Say hello to what could be the next big spam player: SquirrelWaffle, which is spreading with increasing frequency via spam campaigns and infecting systems with a new malware loader.

πŸ“– Read

via "Threat Post".
πŸ•΄ Free Tool Helps Security Teams Measure Their API Attack Surface πŸ•΄

Data Theorem's free API Attack Surface Calculator helps security teams understand potential API exposures.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-23877 β€Ό

Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-22864 β€Ό

A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary web scripts or HTML.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41866 β€Ό

MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.

πŸ“– Read

via "National Vulnerability Database".
❌ Cyber Attack Cripples Iranian Fuel Distribution Network ❌

The incident triggered shutdowns at pumps across the country as attackers flashed the phone number of Supreme Leader Ali Khamenei across video screens.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Attack the block – How a security researcher cracked 70% of urban WiFi networks in one hit πŸ—“οΈ

A new attack takes advantage of weak WiFi passwords

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Identity-Focused Security Controls Prevail πŸ•΄

How identity and access management strategies held up during the pandemic and tips for putting together an identity security road map.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Annual Cyber Risk Survey Finds Businesses Are Sharpening Their Focus on Cybersecurity but Also Reveals Much Room for Improvement in Building Cyber-Resilience πŸ•΄

This year's survey features the highest percentage of cyber insurance buyers since the beginning of the survey 11 years ago.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cynerio Launches IoT Attack Detection and Response Module for Healthcare IoT Devices πŸ•΄

Module helps hospitals identify, contain, and mitigate threats on devices exhibiting malicious or suspicious behavior.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Onfido Acquires EYN to Provide Acoustic-Based Liveness Detection πŸ•΄

Technology will be incorporated into Onfido’s Real Identity Platform.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cyber Readiness Institute Names Karen S. Evans as New Managing Director πŸ•΄

Former assistant secretary for cybersecurity, energy security, and emergency response at US Department of Energy and Homeland Security CIO to lead strategic vision and day-to-day operations.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Avast Business Introduces Network Discovery for SMBs πŸ•΄

Avast's Network Discovery enables network administrators to easily analyze their entire IT network and deploy Avast Business security services.

πŸ“– Read

via "Dark Reading".
πŸ•΄ ThycoticCentrify Integrates Secret Server With Privileged Access Management Platform πŸ•΄

Combination avails Secret Server customers to a range of SaaS services.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-41872 β€Ό

Skyworth Digital Technology Penguin Aurora Box 41502 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.

πŸ“– Read

via "National Vulnerability Database".
🦿 Microsoft warns of new supply chain attacks by Russian-backed Nobelium group 🦿

The cybercrime group behind the SolarWinds hack remains focused on the global IT supply chain, says Microsoft, with 140 resellers and service providers targeted since May.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-41590 β€Ό

In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP server settings. This test function can be used to identify the listening TCP ports available to the server, revealing information about the internal network environment.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38379 β€Ό

The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.

πŸ“– Read

via "National Vulnerability Database".