πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ What is Emotet? πŸ“’

A deep dive into malware's most infamous and prolific strain

πŸ“– Read

via "ITPro".
πŸ“’ Ransomware hit industrial sector the hardest in the third quarter πŸ“’

Cyber criminals are now also targeting the technology sector, which saw a 30% rise in attack volume

πŸ“– Read

via "ITPro".
πŸ“’ F-Secure Safe review: Simple security struggles to outdo Defender πŸ“’

F-Secure Safe doesn’t have the protection or features to stand out against its rivals.

πŸ“– Read

via "ITPro".
πŸ“’ BillQuick billing software exploit lets hackers deploy ransomware πŸ“’

The now-patched critical zero-day vulnerability also leaked sensitive data from the time and billing platform

πŸ“– Read

via "ITPro".
πŸ“’ Telstra to acquire Digicel Pacific for $1.6 billion with help from government πŸ“’

The deal is being called a 'political buy' to counter Chinese influence in the region

πŸ“– Read

via "ITPro".
πŸ“’ Tesco services knocked offline after suspected cyber attack πŸ“’

Customers were left unable to make or cancel orders, or amend their scheduled deliveries

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft to work with community colleges to fill 250,000 cyber security roles πŸ“’

Free course materials will be supplied to every community college in the US

πŸ“– Read

via "ITPro".
πŸ“’ DDoS attacks are crippling UK VoIP operators πŸ“’

Businesses and emergency services are among customers hit by outages at VoIP firms

πŸ“– Read

via "ITPro".
πŸ“’ Critical macOS vulnerability found to bypass SIP restrictions πŸ“’

The flaw lies in how the OS handles software packages and post-installation scripts

πŸ“– Read

via "ITPro".
πŸ“’ Australian Federal Police plots "aggressive" cyber division following law change πŸ“’

New powers allow law enforcement to launch disruptive operations and collect data on suspected criminals

πŸ“– Read

via "ITPro".
πŸ“’ Luxury hotel chain hit twice by hackers after reneging on ransomware payment πŸ“’

The group claims to have information belonging to millions of customers who stayed at Centara hotels and resorts between 2003 and 2021

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft resellers warned of Nobelium attacks on IT supply chain πŸ“’

Microsoft believes that 22,868 attacks have been conducted against 609 partners since July

πŸ“– Read

via "ITPro".
πŸ“’ UK gov must act now to regulate Facebook, says whistleblower πŸ“’

Frances Haugen told members of the Online Safety Bill committee that the social network "is closing the door on us being able to act”

πŸ“– Read

via "ITPro".
πŸ“’ Critical vulnerability discovered in popular CI/CD framework πŸ“’

Flaw in GoCD software delivery pipeline thought to have affected a host of NGOs and Fortune 500 companies

πŸ“– Read

via "ITPro".
πŸ“’ Ransomware gang claims to have hacked the NRA πŸ“’

β€œGrief" gang says it has already leaked some of its stolen data to the dark web

πŸ“– Read

via "ITPro".
β€Ό CVE-2020-25912 β€Ό

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25911 β€Ό

A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33259 β€Ό

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ β€˜Trojan Source’ Bug Threatens the Security of All Code β™ŸοΈ

Virtually all compilers -- programs that transform human-readable source code into computer-executable machine code -- are vulnerable to an insidious attack in which an adversary can introduce targeted vulnerabilities into any software without being detected, new research released today warns. The vulnerability disclosure was coordinated with multiple organizations, some of whom are now releasing updates to address the security weakness.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2021-24789 β€Ό

The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-25019 β€Ό

The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server

πŸ“– Read

via "National Vulnerability Database".