πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-30816 β€Ό

The issue was addressed with improved permissions logic. This issue is fixed in iOS 15 and iPadOS 15. An attacker with physical access to a device may be able to see private contact information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30833 β€Ό

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.0.1. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
❌ Suspected REvil Gang Insider Identified ❌

German investigators have identified a deep-pocketed, big-spending Russian billionaire whom they suspect of being a core member of the REvil ransomware gang.

πŸ“– Read

via "Threat Post".
πŸ•΄ NSA-CISA Series on Securing 5G Cloud Infrastructures πŸ•΄

CISA encourages 5G providers, integrators, and network operators to review the guidance and consider the recommendations.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Tech Companies Create Security Baseline for Enterprise Software πŸ•΄

The Minimum Viable Secure Product is written as a checklist of minimum-security requirements for business-to-business software.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ordr Unveils Cybersecurity Innovations and Ransom-Aware Rapid Assessment Service to Expand Its Leadership In Connected Device Security πŸ•΄

Enhanced ransomware detection, visualization of ransomware communications, and risk customization helps organizations respond to cyberattacks in minutes.

πŸ“– Read

via "Dark Reading".
πŸ•΄ ICS Security Firm Dragos Reaches $1.7B Valuation in Latest Funding Round πŸ•΄

The $200M Series D represents the company's largest funding round to date.

πŸ“– Read

via "Dark Reading".
πŸ•΄ SEO Poisoning Used to Distribute Ransomware πŸ•΄

This tactic β€” used to distribute REvil ransomware and the SolarMarker backdoor β€” is part of a broader increase in such attacks in recent months, researchers say.

πŸ“– Read

via "Dark Reading".
❌ All Sectors Are Now Prey as Cyber Threats Expand Targeting ❌

Aamir Lakhani, security researcher at Fortinet, says no sector is off limits these days: It's time for everyone to strengthen the kill chain.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-36547 β€Ό

A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36551 β€Ό

TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36550 β€Ό

TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36548 β€Ό

A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41194 β€Ό

FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if `create_users=True` and the username is known or guessed. One may upgrade to version 1.0.0 or apply a patch manually to mitigate the vulnerability. For those who cannot upgrade, there is no complete workaround, but a partial mitigation exists. One can disable user creation with `c.FirstUseAuthenticator.create_users = False`, which will only allow login with fully normalized usernames for already existing users prior to jupyterhub-firstuserauthenticator 1.0.0. If any users have never logged in with their normalized username (i.e. lowercase), they will still be vulnerable until a patch or upgrade occurs.

πŸ“– Read

via "National Vulnerability Database".
⚠ Microsoft Edge finally arrives on Linux – β€œOfficial” build lands in repos ⚠

Microsoft Edge for Linux makes an Official landing.

πŸ“– Read

via "Naked Security".
πŸ•΄ 6 Ways to Rewrite the Impossible Job Description πŸ•΄

It's hard enough to fill a cybersecurity position given the talent shortage. But you may be making it harder with a poor job description that turns off would-be candidates.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-23549 β€Ό

IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 file, related to a "Data from Faulting Address controls Branch Selection starting at FORMATS!GetPlugInInfo+0x00000000000047f6".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23546 β€Ό

IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FORMATS!ReadMosaic+0x0000000000000981.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ β€˜Inaction isn’t an option’ – US lawmakers back mandatory standards for transport and logistics cybersecurity πŸ—“οΈ

House Committee on Homeland Security hearing pulls focus on securing β€˜planes, trains, and pipelines’

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-31624 β€Ό

Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the urls parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-22079 β€Ό

Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.

πŸ“– Read

via "National Vulnerability Database".