🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🦿 Secure SSH logins with knockd 🦿

You need to lock down your servers so that only you have access via SSH. One way to help that is with knockd. Jack Wallen shows you how.

📖 Read

via "Tech Republic".
‼ CVE-2018-6058 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11215. Reason: This candidate is a reservation duplicate of CVE-2017-11215. Notes: All CVE users should reference CVE-2017-11215 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-37978 ‼

Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-37980 ‼

Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-37960 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-30631 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2018-6059 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11225. Reason: This candidate is a reservation duplicate of CVE-2017-11225. Notes: All CVE users should reference CVE-2017-11225 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

📖 Read

via "National Vulnerability Database".
‼ CVE-2019-5863 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-37979 ‼

heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-37977 ‼

Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
‼ CVE-2018-6044 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16064. Reason: This candidate is a reservation duplicate of CVE-2018-16064. Notes: All CVE users should reference CVE-2018-16064 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

📖 Read

via "National Vulnerability Database".
🕴 Attackers Flaunt Remote Access Credentials, Threaten Supply Chain 🕴

Attackers advertise access to computers within shipping and logistics companies as the global supply chain struggles to meet post-COVID demands.

📖 Read

via "Dark Reading".
📢 McAfee Total Protection review: Expensive at full price 📢

Protects your PC and includes a decent firewall, but costly and less effective than some rivals

📖 Read

via "ITPro".
📢 What is end-to-end encryption and why is everyone fighting over it? 📢

End-to-end encryption is considered one of the best ways to protect user data, but not everyone thinks it's a good idea

📖 Read

via "ITPro".
📢 17 Windows 10 problems - and how to fix them 📢

Tips and tricks for everything from upgrade issues and freeing up storage, to solving privacy errors and using safe mode

📖 Read

via "ITPro".
📢 Hackers could use new Wslink malware in highly targeted cyber attacks 📢

Malware acts as a server, but its origins baffle boffins

📖 Read

via "ITPro".
📢 Celebrity data leaked after ransomware attack on London's Graff jewellers 📢

Russia-based Conti ransomware group is demanding tens of millions in cryptocurrency

📖 Read

via "ITPro".
📢 Manufacturers forced to improve cyber security of wireless devices under new EU rule 📢

Businesses will have 30 months to comply with the new rules if they want to ship their products to the EU

📖 Read

via "ITPro".
📢 Apple's ad transparency policy has cost Facebook, YouTube, Snap almost $10 billion so far 📢

Estimate from the Financial Times says Facebook has been hit hardest by new rule requiring user consent

📖 Read

via "ITPro".
📢 Microsoft Exchange Servers are being used to distribute SquirrelWaffle malware 📢

Exploiting an unpatched Exchange Server vulnerability and a less-than-foolproof malicious URL strategy is leading to mounting infections in businesses

📖 Read

via "ITPro".
‼ CVE-2021-43267 ‼

An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

📖 Read

via "National Vulnerability Database".