πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38424 β€Ό

The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ β€œTrojan Source” hides flaws in source code from humans πŸ“’

Organizations urged to take action to combat the new threat that could result in SolarWinds-style attacks

πŸ“– Read

via "ITPro".
πŸ“’ Office 365 phishing campaign used stolen Kaspersky Amazon SES token to fool victims πŸ“’

Credentials stolen from users after legitimate-looking email arrives in inboxes

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft unveils Defender for Business at Ignite 2021 πŸ“’

The new security suite is aimed at SMBs struggling to protect themselves in today's cyber security landscape

πŸ“– Read

via "ITPro".
πŸ“’ Mitre reveals 10 worst hardware security weaknesses in 2021 πŸ“’

The list aims to highlight common hardware flaws to help eliminate them from product development cycles

πŸ“– Read

via "ITPro".
πŸ“’ Facebook is shutting down its controversial facial recognition system πŸ“’

The move will see more than a billion facial templates removed from Facebook's records amid a push for more private applications of the technology

πŸ“– Read

via "ITPro".
πŸ“’ BlackMatter ransomware gang claims to have ceased operation πŸ“’

Despite the announcement made via its client portal, experts believe the hacker group will soon be planning a return

πŸ“– Read

via "ITPro".
β€Ό CVE-2020-25368 β€Ό

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25367 β€Ό

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34594 β€Ό

TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34597 β€Ό

Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25366 β€Ό

An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42624 β€Ό

A local buffer overflow vulnerability exists in the latest version of Miniftpd in ftpproto.c through the tmp variable, where a crafted payload can be sent to the affected function.

πŸ“– Read

via "National Vulnerability Database".
❌ Magecart Credit Card Skimmer Avoids VMs to Fly Under the Radar ❌

The Magecart threat actor uses a browser script to evade detection by researchers and sandboxes so it targets only victims’ machines to steal credentials and personal info.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Human rights activists condemn mass denial of service as Sudan’s nationwide internet shutdown enters second week πŸ—“οΈ

β€˜All mobile internet networks are completely cut off,’ one journalist on the ground tells The Daily Swig

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Having Trouble Finding Cybersecurity Talent? You Might Be the Problem πŸ•΄

Hiring managers must rethink old-school practices to find the right candidates and be ready to engage in meaningful conversations about their company's values. Here are three ways to start.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Remote code execution, SQL injection bugs uncovered in Pentaho Business Analytics software πŸ—“οΈ

Penetration test reveals severe issues in Hitachi Vantara’s business solution

πŸ“– Read

via "The Daily Swig".
πŸ•΄ How to Avoid Another Let's Encrypt-Like Meltdown πŸ•΄

Experts weigh in on steps network and security administrators need to take before the next time a root certificate expires.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Appsian Security Announces Acquisition of Q Software, a Leader in JD Edwards Security and Compliance πŸ•΄

The acquisition provides customers of JD Edwards, along with Oracle EBS and Oracle Cloud, with expanded capabilities for data masking, threat detection and response, and real-time analytics across multiple ERP applications.

πŸ“– Read

via "Dark Reading".
❌ Critical Linux Kernel Bug Allows Remote Takeover ❌

The bug (CVE-2021-43267) exists in a TIPC message type that allows Linux nodes to send cryptographic keys to each other.

πŸ“– Read

via "Threat Post".
❌ Free Discord Nitro Offer Used to Steal Steam Credentials ❌

A fake Steam pop-up prompts users to β€˜link’ Discord account for free Nitro subs.

πŸ“– Read

via "Threat Post".