πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Finding Your Niche in Cybersecurity πŸ•΄

With a little patience and research, you can discover a role you love that also protects those around you.

πŸ“– Read

via "Dark Reading".
⚠ Controversial face matchers Clearview set to be fined over $20m ⚠

Scraping data for a facial recognition service? "That's unlawful", concluded both the British and the Australians.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-41679 β€Ό

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41677 β€Ό

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25987 β€Ό

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post Ò€œbodyҀ� and Ò€œtagsҀ� donÒ€ℒt sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41678 β€Ό

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Ransomware vs. Cities: A Cyber War πŸ•΄

As smart cities become the new normal for urban living, they must be resilient against the speed and sophistication of modern cyber threats.

πŸ“– Read

via "Dark Reading".
🦿 Become an ethical hacker for just $13 during this Cyber Week sale 🦿

Now you can learn everything you need to become a master ethical hacker without having to take time away from your current job.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-43202 β€Ό

In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43998 β€Ό

HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Bug Bounty Radar // The latest bug bounty programs for December 2021 πŸ—“οΈ

New web targets for the discerning hacker

πŸ“– Read

via "The Daily Swig".
πŸ“’ Practicality of UK government’s cyber bill criticised by industry experts πŸ“’

The Product Security and Telecommunications Infrastructure (PSTI) Bill falls short in several key areas

πŸ“– Read

via "ITPro".
πŸ“’ Ikea launches "full-scale investigation" into email-based cyber attack πŸ“’

Early evidence seems to indicate a compromise of Microsoft Exchange servers in a reply chain attack campaign

πŸ“– Read

via "ITPro".
πŸ“’ What is smishing? πŸ“’

A closer look at one of the most perilous forms of phishing

πŸ“– Read

via "ITPro".
πŸ“’ RATDispenser evades nine in ten anti-virus engines πŸ“’

Stealth malware deploys key loggers and information stealers

πŸ“– Read

via "ITPro".
πŸ“’ Sky Broadband took almost 18 months to fix serious router flaw πŸ“’

Flaw could expose user’s home network to hackers

πŸ“– Read

via "ITPro".
πŸ“’ GoDaddy data breach exposes over 1.2 million customer details πŸ“’

Attacker had access to admin passwords for over two months

πŸ“– Read

via "ITPro".
πŸ“’ Why the NCSC and telecoms firms are at loggerheads over quantum key distribution πŸ“’

In the face of mixed messages between the public and private sector, should businesses be wary of jumping on the bandwagon?

πŸ“– Read

via "ITPro".
πŸ“’ SMBs urged to update software ahead of Black Friday πŸ“’

NCSC identified 4,151 online shops compromised using vulnerability within e-commerce platform Magento

πŸ“– Read

via "ITPro".
πŸ“’ Pizza chain exposed 100,000 employees' Social Security numbers πŸ“’

Former and current staff at California Pizza Kitchen potentially burned by hackers

πŸ“– Read

via "ITPro".
πŸ“’ Apple sues NSO Group over Pegasus attacks on its customers πŸ“’

The lawsuit claims 'flagrant' violations of US federal and state law from the Israeli firm behind the infamous spyware

πŸ“– Read

via "ITPro".