πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2019-5640 β€Ό

Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

πŸ“– Read

via "National Vulnerability Database".
❌ Imunify360 Bug Leaves Linux Web Servers Open to Code Execution, Takeover ❌

CloudLinux' security platform for Linux-based websites and web servers contains a high-severity PHP deserialization bug.

πŸ“– Read

via "Threat Post".
❌ Attackers Hijack Email Threads Using ProxyLogon/ProxyShell Flaws ❌

Exploiting Microsoft Exchange ProxyLogon & ProxyShell vulnerabilities, attackers are malspamming replies in existing threads and slipping past malicious-email filters.

πŸ“– Read

via "Threat Post".
🦿 Leaders agree that cybersecurity is a business risk, but are they acting on that belief? 🦿

Despite nearly unanimous agreement, there's still a lack of clarity on who is accountable for security incidents and whether previous security investments have paid off, a Gartner survey finds.

πŸ“– Read

via "Tech Republic".
❌ Online Merchants: Prevent Fraudsters from Becoming Holiday Grinches ❌

Black Friday and Cyber Monday approach! Saryu Nayyar, CEO at Gurucul, discusses concerning statistics about skyrocketing online fraud during the festive season.

πŸ“– Read

via "Threat Post".
πŸ•΄ 10 Stocking Stuffers for Security Geeks πŸ•΄

Check out our list of gifts with a big impact for hackers and other techie security professionals.

πŸ“– Read

via "Dark Reading".
πŸ” What's the Biggest Healthcare Security Threat for 2021 And Beyond? πŸ”

We asked 21 cybersecurity experts and healthcare executives what the biggest security threat they're facing in 2021 and beyond is.

πŸ“– Read

via "".
β€Ό CVE-2021-42707 β€Ό

PLC Editor Versions 1.3.8 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42705 β€Ό

PLC Editor Versions 1.3.8 and prior is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38448 β€Ό

The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44143 β€Ό

A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution.

πŸ“– Read

via "National Vulnerability Database".
🦿 GoDaddy security breach impacts more than 1 million WordPress users 🦿

The hosting company has revealed a security incident that exposed the email addresses and customer numbers of 1.2 million Managed WordPress customers.

πŸ“– Read

via "Tech Republic".
β™ŸοΈ Arrest in β€˜Ransom Your Employer’ Email Scheme β™ŸοΈ

In August, KrebsOnSecurity warned that scammers were contacting people and asking them to unleash ransomware inside their employer's network, in exchange for a percentage of any ransom amount paid by the victim company. This week, authorities in Nigeria arrested a suspect in connection with the scheme -- a young man who said he was trying to save up money to help fund a new social network.

πŸ“– Read

via "Krebs on Security".
❌ GoDaddy’s Latest Breach Affects 1.2M Customers ❌

The kingpin domain registrar has logged its fifth cyber-incident since 2018, after an attacker with a compromised password stole email addresses, SSH keys and database logins.

πŸ“– Read

via "Threat Post".
🦿 How to install and use InVID, a plugin to debunk fake news and verify videos and images 🦿

You can make sure you aren't seeing fake news, edited photos or deepfakes with this software. Here's how to install and use it.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Bug Bounties Surge as Firms Compete for Talent πŸ•΄

Companies such as GItLab, which today increased its payment for critical bugs by 75%, are raising bounties and bonuses to attract top-notch researchers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA Urges Critical Infrastructure to Be Alert for Holiday Threats πŸ•΄

CISA and the FBI share steps organizations should take to better protect against security threats during holidays and weekends.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-44147 β€Ό

An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44144 β€Ό

Croatia Control Asterix 2.8.1 has a heap-based buffer over-read, with additional details to be disclosed at a later date.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44150 β€Ό

The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32004 β€Ό

This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning.

πŸ“– Read

via "National Vulnerability Database".