πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Dangerous uXSS bug in Google Chrome’s β€˜New Tab’ page bypassed security features πŸ—“οΈ

β€˜Chrome’s NTP only has a really weak CSP that doesn’t mitigate XSS’

πŸ“– Read

via "The Daily Swig".
🦿 Report: More than half of organizations do not effectively defend against cyberattacks 🦿

Accenture's State of Cyber Resilience study also revealed key traits of cyber resilient leaders. The report found an average of 270 attacks per year per company.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-43130 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43324 β€Ό

LibreNMS through 21.10.2 allows XSS via a widget title.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Mozilla debuts Site Isolation technology with Firefox update πŸ—“οΈ

Sandboxing technology levels up browser security

πŸ“– Read

via "The Daily Swig".
❌ Predicting the Next OWASP API Security Top 10 ❌

API security risk has dramatically evolved in the last two years. Jason Kent, Hacker-in-Residence at Cequence Security, discusses the top API security concerns today and how to address them.

πŸ“– Read

via "Threat Post".
πŸ•΄ Is Sandboxing Dead? πŸ•΄

Organizations should start to evaluate other security measures to replace or complement the once-venerable security sandbox.

πŸ“– Read

via "Dark Reading".
⚠ Facebook to throw out face recognition, delete all template data ⚠

Publicity stunt? Or privacy progress?

πŸ“– Read

via "Naked Security".
⚠ Europol announces β€œtargeting” of 12 suspects in ransomware attacks ⚠

More anti-ransomware activity by law enforcement, this time in Switzerland and Ukraine.

πŸ“– Read

via "Naked Security".
πŸ” CISA: Patch These Bugs Now πŸ”

CISA is giving federal agencies between two weeks and six months to patch known exploited vulnerabilities.

πŸ“– Read

via "".
πŸ›  Clam AntiVirus Toolkit 0.104.1 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2021-37147 β€Ό

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41585 β€Ό

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26786 β€Ό

An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbitrary code via the purchace code to the config.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23680 β€Ό

An issue was discovered in function StartPage in text2pdf.c in pdfcorner text2pdf 1.1, allows attackers to cause denial of service or possibly other undisclosed impacts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20982 β€Ό

Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40985 β€Ό

Buffer overflow vulnerability in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38161 β€Ό

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23126 β€Ό

Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27836 β€Ό

An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37149 β€Ό

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

πŸ“– Read

via "National Vulnerability Database".