πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Security breach at trading platform Robinhood sparks phishing fears πŸ—“οΈ

Social engineering attack exposes email addresses of five million investors

πŸ“– Read

via "The Daily Swig".
❌ Robinhood Trading Platform Data Breach Hits 7M Customers ❌

The cyberattacker attempted to extort the company after socially engineering a customer service employee to gain access to email addresses and more.

πŸ“– Read

via "Threat Post".
πŸ•΄ The State of the CISO πŸ•΄

Dark Reading survey shows security officer influence is on the rise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Building Bridges to a More Secure Hybrid Workplace πŸ•΄

Wherever workers chose to do their jobs, they need technology that's unobtrusive, secure by design, and intuitive to use.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-43519 β€Ό

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3641 β€Ό

Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to cause a denial of service. This issue affects: Bitdefender GravityZone version 7.1.2.33 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43114 β€Ό

FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-18916 β€Ό

A potential security vulnerability has been identified for HP LaserJet Solution Software (for certain HP LaserJet Printers) which may lead to unauthorized elevation of privilege on the client.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ SafeBreach Closes $53.5 Million Series D in New Funding to Fuel Momentum πŸ•΄

The new capital will fuel the company's plans to expand its market footprint to new geographies and evolve its offerings in response to client needs.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ bZx crypto heist results in reported losses of more than $55 million πŸ—“οΈ

BSC and Polygon funds drained – but Ethereum contracts β€˜safe’ – following phishing attack

πŸ“– Read

via "The Daily Swig".
❌ The New Frontier of Enterprise Risk: Nth Parties ❌

The average number of vulnerabilities discovered in a Cyberpion scan of external Fortune 500 networks (such as cloud systems) was 296, many critical (with the top of the scale weighing in at a staggering 7,500).

πŸ“– Read

via "Threat Post".
❌ Security Tool Guts: How Much Should Customers See? ❌

Yaron Kassner, CTO of Silverfort, delves into the pros and cons of transparency when it comes to cybersecurity tools’ algorithms.

πŸ“– Read

via "Threat Post".
🦿 US amps up war on ransomware with charges against REvil attackers 🦿

One person fingered for the July 2021 attack against Kaseya is in custody, while the other individual is still at large.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 83% of Critical Infrastructure Organizations Suffered Breaches, 2021 Cybersecurity Research Reveals πŸ•΄

Supply chain and third-party risk is a major threat to operational technology.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-43193 β€Ό

In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43201 β€Ό

In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43187 β€Ό

In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43186 β€Ό

JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43183 β€Ό

In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-16240 β€Ό

A Buffer Overflow and Information Disclosure issue exists in HP OfficeJet Pro Printers before 001.1937C, and HP PageWide Managed Printers and HP PageWide Pro Printers before 001.1937D exists; A maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain circumstances, the printer produces a core dump to a local device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43197 β€Ό

In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.

πŸ“– Read

via "National Vulnerability Database".