πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Campaigning lawyers launch counter-offensive against software patent trolls πŸ—“οΈ

Stemming the tide of β€˜stupid software patents and the trolls they feed’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Could Cyber Diplomacy Be the Ultimate Answer to American Ransomware Woes? πŸ•΄

Incentives for good conduct and deterrents for bad behavior in cyberspace are impossible to effectively establish and enforce without international collaboration and commitment.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-32482 β€Ό

Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32483 β€Ό

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30132 β€Ό

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29243 β€Ό

Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22051 β€Ό

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37850 β€Ό

ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to the system to stop the ESET daemon, effectively disabling the protection of the ESET security product until a system reboot.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29994 β€Ό

Cloudera Hue 4.6.0 allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32481 β€Ό

Cloudera Hue 4.6.0 allows XSS via the type parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Valeo Networks Acquires On Time Tech, Accelerating National Growth Strategy πŸ•΄

Through this latest acquisition, the company adds two more California locations.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Mozilla disables β€˜low usage’ encryption feature to resolve Thunderbird HTTP/2 vulnerability πŸ—“οΈ

Multiple flaws in email client resolved with security update

πŸ“– Read

via "The Daily Swig".
❌ Zoho Password Manager Flaw Torched by Godzilla Webshell ❌

A new campaign is prying apart a known security vulnerability in the Zoho ManageEngine ADSelfService Plus password manager, researchers warned over the weekend. The threat actors have managed to exploit the Zoho weakness in at least nine global entities across critical sectors so far (technology, defense, healthcare, energy and education), deploying the Godzilla webshell and […]

πŸ“– Read

via "Threat Post".
πŸ•΄ Arctic Wolf Security Operations Cloud Reaches Massive Scale and a Global Footprint πŸ•΄

Global business momentum and technical advancements position the Arctic Wolf platform as a category-defining Security Operations solution

πŸ“– Read

via "Dark Reading".
πŸ•΄ Kaspersky Finds DDoS Attacks in Q3 Grow by 24%, Become More Sophisticated πŸ•΄

The total number of smart attacks (advanced DDoS attacks that are often targeted) increased by 31% when compared to the same period last year.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Banking Malware Threats Surging as Mobile Banking Increases – Nokia Threat Intelligence Report πŸ•΄

The Nokia 2021 Threat Intelligence Report announced today shows that banking malware threats are sharply increasing as cyber criminals target the rising popularity of mobile banking on smartphones, with plots aimed at stealing personal banking credentials and credit card information.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-41733 β€Ό

Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28023 β€Ό

Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28024 β€Ό

Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25979 β€Ό

Apostrophe CMS versions between 2.63.0 to 3.3.1 affected by an insufficient session expiration vulnerability, which allows unauthenticated remote attackers to hijack recently logged-in users' sessions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42770 β€Ό

A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the authentication tester.

πŸ“– Read

via "National Vulnerability Database".