πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Risk Quantification: A Powerful Tool in Your Cyberthreat Defense Arsenal πŸ•΄

Three ways that understanding your cyber-risk in real dollars can help your organization survive the threat of ransomware and other attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-36697 β€Ό

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36698 β€Ό

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Valtix Delivers Free Cloud Security for Departmental, Development, and Test Applications πŸ•΄

Company aims to make cloud network security more accessible to all organizations.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Dangerous uXSS bug in Google Chrome’s β€˜New Tab’ page bypassed security features πŸ—“οΈ

β€˜Chrome’s NTP only has a really weak CSP that doesn’t mitigate XSS’

πŸ“– Read

via "The Daily Swig".
🦿 Report: More than half of organizations do not effectively defend against cyberattacks 🦿

Accenture's State of Cyber Resilience study also revealed key traits of cyber resilient leaders. The report found an average of 270 attacks per year per company.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-43130 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43324 β€Ό

LibreNMS through 21.10.2 allows XSS via a widget title.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Mozilla debuts Site Isolation technology with Firefox update πŸ—“οΈ

Sandboxing technology levels up browser security

πŸ“– Read

via "The Daily Swig".
❌ Predicting the Next OWASP API Security Top 10 ❌

API security risk has dramatically evolved in the last two years. Jason Kent, Hacker-in-Residence at Cequence Security, discusses the top API security concerns today and how to address them.

πŸ“– Read

via "Threat Post".
πŸ•΄ Is Sandboxing Dead? πŸ•΄

Organizations should start to evaluate other security measures to replace or complement the once-venerable security sandbox.

πŸ“– Read

via "Dark Reading".
⚠ Facebook to throw out face recognition, delete all template data ⚠

Publicity stunt? Or privacy progress?

πŸ“– Read

via "Naked Security".
⚠ Europol announces β€œtargeting” of 12 suspects in ransomware attacks ⚠

More anti-ransomware activity by law enforcement, this time in Switzerland and Ukraine.

πŸ“– Read

via "Naked Security".
πŸ” CISA: Patch These Bugs Now πŸ”

CISA is giving federal agencies between two weeks and six months to patch known exploited vulnerabilities.

πŸ“– Read

via "".
πŸ›  Clam AntiVirus Toolkit 0.104.1 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2021-37147 β€Ό

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41585 β€Ό

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26786 β€Ό

An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbitrary code via the purchace code to the config.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23680 β€Ό

An issue was discovered in function StartPage in text2pdf.c in pdfcorner text2pdf 1.1, allows attackers to cause denial of service or possibly other undisclosed impacts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20982 β€Ό

Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40985 β€Ό

Buffer overflow vulnerability in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.

πŸ“– Read

via "National Vulnerability Database".