πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2018-12008 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-11900 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-9092 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Baffle's Data Privacy Cloud Protects Data for Amazon Redshift Customers πŸ•΄

Amazon Redshift customers can use Baffle’s Data Privacy Cloud to secure the data pipeline as source data is migrated to Redshift and used for data analytics.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-44140 β€Ό

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40369 β€Ό

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.0 or later.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ VMware addresses SSRF, arbitrary file read flaws in vCenter Server πŸ—“οΈ

β€˜Important’ severity flaws both reside in the vSphere Web Client

πŸ“– Read

via "The Daily Swig".
❌ Attackers Actively Target Windows Installer Zero-Day ❌

Researcher discovered a β€œmore powerful” variant of an elevation-of-privilege flaw for which Microsoft released a botched patch earlier this month.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Cyberstalking study: UK residents most accepting of spyware to track partners’ movements πŸ—“οΈ

Report from cybersecurity firm Kaspersky reveals worrying attitudes towards spyware usage

πŸ“– Read

via "The Daily Swig".
πŸ•΄ When Will Security Frameworks Catch Up With the New Cybersecurity Normal? πŸ•΄

Standards need to reflect that most endpoints will be remote and/or wireless.

πŸ“– Read

via "Dark Reading".
πŸ” DG Insights to Help Leaders Assess DLP Effectiveness πŸ”

Digital Guardian's Managed Security Program customers can now receive a weekly email that gives further insight into their organization's data movement.

πŸ“– Read

via "".
🦿 Apple needs to un-Mac-ify security and privacy in Safari 🦿

Safari is a good browser, but it could be better. Unfortunately, one area that requires improvement is the un-Mac-ifying of the privacy settings. Find out what Jack Wallen means by this.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Decrypting diversity: One in five UK infosec professionals say they’ve experienced discrimination at work πŸ—“οΈ

Report states diversity and inclusion within the industry is lagging behind

πŸ“– Read

via "The Daily Swig".
❌ Apple’s NSO Group Lawsuit Amps Up Pressure on Pegasus Spyware-Maker ❌

Just weeks after a judge ruled that NSO Group did not have immunity in a suit brought by Facebook subsidiary WhatsApp, Apple is adding significant weight to the company's woes.

πŸ“– Read

via "Threat Post".
❌ GoDaddy Breach Widens to Include Reseller Subsidiaries ❌

Customers of several brands that resell GoDaddy Managed WordPress have also been caught up in the big breach, in which millions of emails, passwords and more were stolen.

πŸ“– Read

via "Threat Post".
πŸ›  GNU Privacy Guard 2.2.33 πŸ› 

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions. This is the LTS release.

πŸ“– Read

via "Packet Storm Security".
⚠ GoDaddy admits to password breach: check your Managed WordPress site! ⚠

GoDaddy found crooks in its network, and kicked them out - but not before they'd been in there for six weeks.

πŸ“– Read

via "Naked Security".
⚠ Check your patches – public exploit now out for critical Exchange bug ⚠

It was a zero-day bug until Patch Tuesday, now there's an anyone-can-use-it exploit. Don't be the one who hasn't patched.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-20840 β€Ό

Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20843 β€Ό

Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3554 β€Ό

Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender Unified Endpoint versions prior to 6.2.21.160. Bitdefender GravityZone versions prior to 6.24.1-1.

πŸ“– Read

via "National Vulnerability Database".