πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Panasonic Hit in Data Breach πŸ•΄

Tech firm reveals that data on one of its file servers was accessed by attackers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Over 1,000 Individuals Arrested in Global Cybercrime-Fighting Operation πŸ•΄

HAECHI-II initiative represents Interpol's stepped-up efforts to tackle the operators of financially motivated online scams and other cyberattacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google Analyzes Methods Behind GCP Workload Attacks πŸ•΄

The vast majority of cloud workload compromises stem from poor security configurations or compromised passwords, while cryptojacking is the common payload, research shows.

πŸ“– Read

via "Dark Reading".
πŸ•΄ IKEA Email Systems Targeted in Cyberattack πŸ•΄

Attackers are reportedly targeting IKEA employees in a phishing campaign that leverages stolen reply-chain emails.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Phishing Remains the Most Common Cause of Data Breaches, Survey Says πŸ•΄

Despite heightened concerns over ransomware, fewer organizations in a Dark Reading survey reported being an actual victim of a ransomware attack over the past year.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 9 out of 10 Healthcare Organizations Provide Telehealth Services, Yet Almost Half Face Patients' Mistrust Toward Privacy πŸ•΄

Kaspersky surveyed healthcare decision-makers to learn how the digital transformation of the industry is going and which problems they believe should be solved to create a world in which everyone can gain access to quality care.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-44427 β€Ό

An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Armis Now Valued at $3.4B πŸ•΄

One Equity Partners led the $300 million round, increasing the valuation of Armis from the $2 billion valuation it achieved less than 8 months ago.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Stellar Cyber Raises $38M Series B to Address Need to Provide 360-Degree Visibility Across Entire Attack Surface πŸ•΄

Oversubscribed round, including Samsung, rewards technical innovations and rapid market adoption, positions company for continued leadership.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-3727 β€Ό

# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes contained the proper symbols, they could trigger command injection. Given that they're an external API, it's not possible to know if the quotes are safe to use. **Fixed in**: [72928432](https://github.com/ohmyzsh/ohmyzsh/commit/72928432). **Impacted areas**: - `rand-quote` plugin (`quote` function). - `hitokoto` plugin (`hitokoto` function).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3769 β€Ό

# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be exploited. **Fixed in**: [b3ba9978](https://github.com/ohmyzsh/ohmyzsh/commit/b3ba9978). **Impacted areas**: - `pygmalion` theme. - `pygmalion-virtualenv` theme. - `refined` theme.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3725 β€Ό

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject to command injection. Impacted areas: - Functions pop_past and pop_future in dirhistory plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3726 β€Ό

# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used securely, but custom user code could use the `title` function in a way that is unsafe. **Fixed in**: [a263cdac](https://github.com/ohmyzsh/ohmyzsh/commit/a263cdac). **Impacted areas**: - `title` function in `lib/termsupport.zsh`. - Custom user code using the `title` function.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ HP printer vulnerabilities left enterprise networks open to abuse via β€˜cross-site printing’ attack πŸ—“οΈ

Hardware hacking technique gets points for innovation, although some degree of social engineering is required

πŸ“– Read

via "The Daily Swig".
🦿 Cisco releases Shared Signals and Events reference document to solve "head on a swivel" problem 🦿

Security standard could improve interoperability among security vendors and expand support for zero trust approach to security.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Panasonic admits data breach after attackers gain access to file server πŸ—“οΈ

Reports suggest that intrusion may have persisted for months

πŸ“– Read

via "The Daily Swig".
πŸ›  Stegano 0.10.1 πŸ› 

Stegano is a basic Python Steganography module. Stegano implements two methods of hiding: using the red portion of a pixel to hide ASCII messages, and using the Least Significant Bit (LSB) technique. It is possible to use a more advanced LSB method based on integers sets. The sets (Sieve of Eratosthenes, Fermat, Carmichael numbers, etc.) are used to select the pixels used to hide the information.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Wapiti Web Application Vulnerability Scanner 3.0.8 πŸ› 

Wapiti is a web application vulnerability scanner. It will scan the web pages of a deployed web application and will fuzz the URL parameters and forms to find common web vulnerabilities.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Finding Your Niche in Cybersecurity πŸ•΄

With a little patience and research, you can discover a role you love that also protects those around you.

πŸ“– Read

via "Dark Reading".
⚠ Controversial face matchers Clearview set to be fined over $20m ⚠

Scraping data for a facial recognition service? "That's unlawful", concluded both the British and the Australians.

πŸ“– Read

via "Naked Security".