πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Darktrace Reports 30% More Ransomware Attacks Targeting Organizations During the Holiday Period πŸ•΄

Researchers also observed a 70% average increase in attempted ransomware attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-36129 β€Ό

AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36135 β€Ό

AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36134 β€Ό

AOM v2.0.1 was discovered to contain a segmentation violation via the component aom_dsp/x86/obmc_sad_avx2.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36131 β€Ό

AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28237 β€Ό

LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28236 β€Ό

LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36130 β€Ό

AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36133 β€Ό

AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Ransomware, Carding, and Initial Access Brokers: Group-IB Presents Report on Trending Crimes πŸ•΄

Report explores cybercrime developments from the second half of 2020 through the first half of 2021.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ FTC implements tougher data protection rules to safeguard customer information πŸ—“οΈ

New requirements for financial institutions include vulnerability assessments, employee training

πŸ“– Read

via "The Daily Swig".
❌ Threat Group Takes Aim Again at Cloud Platform Provider Zoho ❌

Attackers that previously targeted the cloud platform provider have shifted their focus to additional products in the company’s portfolio.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-44020 β€Ό

An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44019 and 44021.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4000 β€Ό

showdoc is vulnerable to URL Redirection to Untrusted Site

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44021 β€Ό

An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44019 and 44020.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43673 β€Ό

dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of exit function will be print for the user exit(json_encode($return)).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43772 β€Ό

Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without any detection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44022 β€Ό

A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected installations, leading to a denial-of-service (DoS). Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44019 β€Ό

An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44020 and 44021.

πŸ“– Read

via "National Vulnerability Database".
🦿 How to avoid being a hacker's next target: Don't overshare information on business social media 🦿

When using LinkedIn and other social media accounts for professional reasons, there are important factors to consider about securing your personal data. Learn how to protect yourself from a hacker.

πŸ“– Read

via "Tech Republic".
πŸ” Friday Five 12/2 πŸ”

$31 in digital coin stolen, an insider extortion attack, and a new cybersecurity resource for healthcare workers - catch up on the infosec news of the week with the Friday Five!

πŸ“– Read

via "".