πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-23719 β€Ό

Cross site scripting (XSS) vulnerability in application/controllers/AdminController.php in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the bbsmeta parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-12814 β€Ό

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifically crafted requests to the web GUI.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41019 β€Ό

An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41023 β€Ό

A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41022 β€Ό

A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-15940 β€Ό

An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36186 β€Ό

A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36184 β€Ό

A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
❌ Ransomware Gangs Target Corporate Financial Activities ❌

The FBI is warning about a fresh extortion tactic: threatening to tank share prices for publicly held companies.

πŸ“– Read

via "Threat Post".
πŸ•΄ Female-Founded Cybersecurity Startup Wabbi Raises Over $2M in Seed Funding πŸ•΄

Wabbi enables companies to assimilate application security processes into development pipelines to produce and scale application security across enterprises.

πŸ“– Read

via "Dark Reading".
πŸ•΄ FBI: Ransomware Actors Use Financial Events to Extort Victims πŸ•΄

Attackers research financial information about an organization and threaten to disclose it if they don't receive ransom quickly.

πŸ“– Read

via "Dark Reading".
πŸ•΄ China Hosts More Malware Than Russia: Findings from DNSFilter's 2021 Domain Threat Report πŸ•΄

Cryptomining has also had a resurgence over the last year as blockchain technology and NFTs rise in popularity.

πŸ“– Read

via "Dark Reading".
❌ Squid Game Crypto Scammers Rips Off Investors for Millions ❌

Anti-dumping code kept investors from selling SQUID while fraudsters cashed out.

πŸ“– Read

via "Threat Post".
πŸ‘1
πŸ•΄ 44% of Parents Struggle to Follow Tech Rules They Set for Their Kids πŸ•΄

Parents perceive norms of behavior to be different for themselves and their children, according to Kaspersky..

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Expands Security to AWS in Multicloud Push πŸ•΄

Microsoft will expand its cloud security tools to AWS within a suite called Defender for Cloud and launch a new Defender for Business in preview later this month.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Dragos Launches ServiceNow’s OT Asset Discovery App πŸ•΄

Integration with Dragos Platform will help joint customers to expand the visibility of ICS/OT assets.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Vaultree Raises $3.3M for Encryption Solution πŸ•΄

The company's platform uses Enhanced Searchable Symmetric Encryption (ESSE) and Fully Homomorphic Encryption (FHE) technologies.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Executive Women's Forum on Information Security, Risk Management & Privacy Elects Three Board Advisers πŸ•΄

Security executives hail from Target, Eli Lilley, and SecurityCurve/SaltCybersecurity.

πŸ“– Read

via "Dark Reading".
🦿 Secure SSH logins with knockd 🦿

You need to lock down your servers so that only you have access via SSH. One way to help that is with knockd. Jack Wallen shows you how.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2018-6058 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11215. Reason: This candidate is a reservation duplicate of CVE-2017-11215. Notes: All CVE users should reference CVE-2017-11215 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37978 β€Ό

Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".