πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-3726 β€Ό

# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used securely, but custom user code could use the `title` function in a way that is unsafe. **Fixed in**: [a263cdac](https://github.com/ohmyzsh/ohmyzsh/commit/a263cdac). **Impacted areas**: - `title` function in `lib/termsupport.zsh`. - Custom user code using the `title` function.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ HP printer vulnerabilities left enterprise networks open to abuse via β€˜cross-site printing’ attack πŸ—“οΈ

Hardware hacking technique gets points for innovation, although some degree of social engineering is required

πŸ“– Read

via "The Daily Swig".
🦿 Cisco releases Shared Signals and Events reference document to solve "head on a swivel" problem 🦿

Security standard could improve interoperability among security vendors and expand support for zero trust approach to security.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Panasonic admits data breach after attackers gain access to file server πŸ—“οΈ

Reports suggest that intrusion may have persisted for months

πŸ“– Read

via "The Daily Swig".
πŸ›  Stegano 0.10.1 πŸ› 

Stegano is a basic Python Steganography module. Stegano implements two methods of hiding: using the red portion of a pixel to hide ASCII messages, and using the Least Significant Bit (LSB) technique. It is possible to use a more advanced LSB method based on integers sets. The sets (Sieve of Eratosthenes, Fermat, Carmichael numbers, etc.) are used to select the pixels used to hide the information.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Wapiti Web Application Vulnerability Scanner 3.0.8 πŸ› 

Wapiti is a web application vulnerability scanner. It will scan the web pages of a deployed web application and will fuzz the URL parameters and forms to find common web vulnerabilities.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Finding Your Niche in Cybersecurity πŸ•΄

With a little patience and research, you can discover a role you love that also protects those around you.

πŸ“– Read

via "Dark Reading".
⚠ Controversial face matchers Clearview set to be fined over $20m ⚠

Scraping data for a facial recognition service? "That's unlawful", concluded both the British and the Australians.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-41679 β€Ό

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41677 β€Ό

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25987 β€Ό

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post Ò€œbodyҀ� and Ò€œtagsҀ� donÒ€ℒt sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41678 β€Ό

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Ransomware vs. Cities: A Cyber War πŸ•΄

As smart cities become the new normal for urban living, they must be resilient against the speed and sophistication of modern cyber threats.

πŸ“– Read

via "Dark Reading".
🦿 Become an ethical hacker for just $13 during this Cyber Week sale 🦿

Now you can learn everything you need to become a master ethical hacker without having to take time away from your current job.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-43202 β€Ό

In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43998 β€Ό

HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Bug Bounty Radar // The latest bug bounty programs for December 2021 πŸ—“οΈ

New web targets for the discerning hacker

πŸ“– Read

via "The Daily Swig".
πŸ“’ Practicality of UK government’s cyber bill criticised by industry experts πŸ“’

The Product Security and Telecommunications Infrastructure (PSTI) Bill falls short in several key areas

πŸ“– Read

via "ITPro".
πŸ“’ Ikea launches "full-scale investigation" into email-based cyber attack πŸ“’

Early evidence seems to indicate a compromise of Microsoft Exchange servers in a reply chain attack campaign

πŸ“– Read

via "ITPro".
πŸ“’ What is smishing? πŸ“’

A closer look at one of the most perilous forms of phishing

πŸ“– Read

via "ITPro".