πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2018-13957 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-13881 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-13956 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42784 β€Ό

OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform command injection via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-13922 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-13949 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-13953 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-9121 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-13965 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-11885 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-13964 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-12008 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-11900 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-9092 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Baffle's Data Privacy Cloud Protects Data for Amazon Redshift Customers πŸ•΄

Amazon Redshift customers can use Baffle’s Data Privacy Cloud to secure the data pipeline as source data is migrated to Redshift and used for data analytics.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-44140 β€Ό

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40369 β€Ό

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.0 or later.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ VMware addresses SSRF, arbitrary file read flaws in vCenter Server πŸ—“οΈ

β€˜Important’ severity flaws both reside in the vSphere Web Client

πŸ“– Read

via "The Daily Swig".
❌ Attackers Actively Target Windows Installer Zero-Day ❌

Researcher discovered a β€œmore powerful” variant of an elevation-of-privilege flaw for which Microsoft released a botched patch earlier this month.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Cyberstalking study: UK residents most accepting of spyware to track partners’ movements πŸ—“οΈ

Report from cybersecurity firm Kaspersky reveals worrying attitudes towards spyware usage

πŸ“– Read

via "The Daily Swig".
πŸ•΄ When Will Security Frameworks Catch Up With the New Cybersecurity Normal? πŸ•΄

Standards need to reflect that most endpoints will be remote and/or wireless.

πŸ“– Read

via "Dark Reading".