πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-34597 β€Ό

Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25366 β€Ό

An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42624 β€Ό

A local buffer overflow vulnerability exists in the latest version of Miniftpd in ftpproto.c through the tmp variable, where a crafted payload can be sent to the affected function.

πŸ“– Read

via "National Vulnerability Database".
❌ Magecart Credit Card Skimmer Avoids VMs to Fly Under the Radar ❌

The Magecart threat actor uses a browser script to evade detection by researchers and sandboxes so it targets only victims’ machines to steal credentials and personal info.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Human rights activists condemn mass denial of service as Sudan’s nationwide internet shutdown enters second week πŸ—“οΈ

β€˜All mobile internet networks are completely cut off,’ one journalist on the ground tells The Daily Swig

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Having Trouble Finding Cybersecurity Talent? You Might Be the Problem πŸ•΄

Hiring managers must rethink old-school practices to find the right candidates and be ready to engage in meaningful conversations about their company's values. Here are three ways to start.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Remote code execution, SQL injection bugs uncovered in Pentaho Business Analytics software πŸ—“οΈ

Penetration test reveals severe issues in Hitachi Vantara’s business solution

πŸ“– Read

via "The Daily Swig".
πŸ•΄ How to Avoid Another Let's Encrypt-Like Meltdown πŸ•΄

Experts weigh in on steps network and security administrators need to take before the next time a root certificate expires.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Appsian Security Announces Acquisition of Q Software, a Leader in JD Edwards Security and Compliance πŸ•΄

The acquisition provides customers of JD Edwards, along with Oracle EBS and Oracle Cloud, with expanded capabilities for data masking, threat detection and response, and real-time analytics across multiple ERP applications.

πŸ“– Read

via "Dark Reading".
❌ Critical Linux Kernel Bug Allows Remote Takeover ❌

The bug (CVE-2021-43267) exists in a TIPC message type that allows Linux nodes to send cryptographic keys to each other.

πŸ“– Read

via "Threat Post".
❌ Free Discord Nitro Offer Used to Steal Steam Credentials ❌

A fake Steam pop-up prompts users to β€˜link’ Discord account for free Nitro subs.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Majority of consumer IoT vendors still lack vulnerability disclosure programs – report πŸ—“οΈ

Dismal findings appear to vindicate global efforts to regulate the sector

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ US federal agencies ordered to patch hundreds of actively exploited vulnerabilities πŸ—“οΈ

CISA directive establishes tight patching deadlines

πŸ“– Read

via "The Daily Swig".
🦿 US government orders federal agencies to patch 100s of vulnerabilities 🦿

The Cybersecurity and Infrastructure Security Agency is maintaining a database of known security flaws with details on how and when federal agencies and departments should patch them.

πŸ“– Read

via "Tech Republic".
🦿 2022 will be the year of convergence between edge, IoT and networking tech, Forrester predicts 🦿

IoT tech will help reduce emissions, satellite internet will challenge 5G, the chip shortage will continue and more will happen in 2022 as pandemic recovery continues to move slowly forward.

πŸ“– Read

via "Tech Republic".
β™ŸοΈ β€˜Tis the Season for the Wayward Package Phish β™ŸοΈ

The holiday shopping season always means big business for phishers, who tend to find increased success this time of year with a time-honored lure about a wayward package that needs redelivery. Here's a look at a fairly elaborate SMS-based phishing scam that spoofs FedEx in a bid to extract personal and financial information from unwary recipients.

πŸ“– Read

via "Krebs on Security".
⚠ Facebook to throw out face recognition, delete all template data ⚠

Publicity stunt? Or privacy progress?

πŸ“– Read

via "Naked Security".
⚠ S3 Ep57: Europol v. Ransomware, Shrootless bug, and Linux browser flamewars [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
❌ US Blacklists Pegasus Spyware Maker ❌

NSO Group plans to fight the trade ban, saying it's "dismayed" and clinging to the mantra that its tools actually help to prevent terrorism and crime.

πŸ“– Read

via "Threat Post".
❌ 3 Guideposts for Building a Better Incident-Response Plan ❌

Invest and practice: Grant Oviatt, director of incident-response engagements at Red Canary, lays out the key building blocks for effective IR.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-40115 β€Ό

A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

πŸ“– Read

via "National Vulnerability Database".