πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-33209 β€Ό

An issue was discovered in Fimer Aurora Vision before 2.97.10. The response to a failed login attempt discloses whether the username or password is wrong, helping an attacker to enumerate usernames. This can make a brute-force attack easier.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33210 β€Ό

An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information without authentication by reading the response of APIs from a kiosk view of a plant.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36192 β€Ό

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS.

πŸ“– Read

via "National Vulnerability Database".
❌ Report: BlackMatter Ransomware Gang Goes Dark, Again ❌

The former DarkSide cybercriminal group will shut down due to increased pressure from authorities, who may have nabbed a key team member.

πŸ“– Read

via "Threat Post".
🦿 Ransomware gangs leaking sensitive financial information to extort organizations 🦿

Attackers will threaten to release confidential data that could affect a company's stock price to pressure them to pay the ransom, says the FBI.

πŸ“– Read

via "Tech Republic".
🦿 Digital natives more likely to fall for phishing attacks at work than their Gen X and Boomer colleagues 🦿

SailPoint survey finds that younger workers also are more likely to use company email addresses for online shopping and subscriptions.

πŸ“– Read

via "Tech Republic".
🦿 Rootkits: Expensive to build, cheap to rent 🦿

Positive Technology analysts found ready-made malware for any budget as well as the option to have a custom-build rootkit on Dark Web forums.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ RCE vulnerability found in Sitecore enterprise CMS software πŸ—“οΈ

Vendor update is available now

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Risk Quantification: A Powerful Tool in Your Cyberthreat Defense Arsenal πŸ•΄

Three ways that understanding your cyber-risk in real dollars can help your organization survive the threat of ransomware and other attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-36697 β€Ό

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36698 β€Ό

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Valtix Delivers Free Cloud Security for Departmental, Development, and Test Applications πŸ•΄

Company aims to make cloud network security more accessible to all organizations.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Dangerous uXSS bug in Google Chrome’s β€˜New Tab’ page bypassed security features πŸ—“οΈ

β€˜Chrome’s NTP only has a really weak CSP that doesn’t mitigate XSS’

πŸ“– Read

via "The Daily Swig".
🦿 Report: More than half of organizations do not effectively defend against cyberattacks 🦿

Accenture's State of Cyber Resilience study also revealed key traits of cyber resilient leaders. The report found an average of 270 attacks per year per company.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-43130 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43324 β€Ό

LibreNMS through 21.10.2 allows XSS via a widget title.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Mozilla debuts Site Isolation technology with Firefox update πŸ—“οΈ

Sandboxing technology levels up browser security

πŸ“– Read

via "The Daily Swig".
❌ Predicting the Next OWASP API Security Top 10 ❌

API security risk has dramatically evolved in the last two years. Jason Kent, Hacker-in-Residence at Cequence Security, discusses the top API security concerns today and how to address them.

πŸ“– Read

via "Threat Post".
πŸ•΄ Is Sandboxing Dead? πŸ•΄

Organizations should start to evaluate other security measures to replace or complement the once-venerable security sandbox.

πŸ“– Read

via "Dark Reading".
⚠ Facebook to throw out face recognition, delete all template data ⚠

Publicity stunt? Or privacy progress?

πŸ“– Read

via "Naked Security".
⚠ Europol announces β€œtargeting” of 12 suspects in ransomware attacks ⚠

More anti-ransomware activity by law enforcement, this time in Switzerland and Ukraine.

πŸ“– Read

via "Naked Security".