πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-3980 β€Ό

elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

πŸ“– Read

via "National Vulnerability Database".
❌ What Are Your Top Cloud Security Challenges? Threatpost Poll ❌

We want to know what your biggest cloud security concerns and challenges are, and how your company is dealing with them. Weigh in with our exclusive poll!

πŸ“– Read

via "Threat Post".
⚠ Mozilla patches critical β€œBigSig” cryptographic bug: Here’s how to track it down and fix it ⚠

Mozilla's cryptographic code had a critical bug. Problem is that numerous apps are affected and may need patching individually.

πŸ“– Read

via "Naked Security".
🦿 How well do you know your APIs? Not well enough, says Cisco 🦿

Many APIs are openly accessible online, and that means big chunks of your apps are, too. Cisco's Vijoy Pandey has tools and tips to help businesses get visibility into their APIs.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Logiq.ai Tackles Observability Problem With LogFlow πŸ•΄

LogFlow addresses data risks associated with machine data pipelines.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-29756 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29867 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38909 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209706.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20470 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20493 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197794.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29719 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29716 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.

πŸ“– Read

via "National Vulnerability Database".
❌ Omicron Phishing Scam Already Spotted in UK ❌

Omicron COVID-19 variant anxiety inspires new phishing scam offering fake NHS tests to steal data.

πŸ“– Read

via "Threat Post".
πŸ•΄ How Criminals Are Using Synthetic Identities for Fraud πŸ•΄

Organizations must improve their cybersecurity protocols to detect fraudulent identities and make sure they're safeguarding their consumers’ personal information.

πŸ“– Read

via "Dark Reading".
❌ Pandemic-Influenced Car Shopping: Just Use the Manufacturer API ❌

Jason Kent, hacker-in-residence at Cequence, found a way to exploit a Toyota API to get around the hassle of car shopping in the age of supply-chain woes.

πŸ“– Read

via "Threat Post".
πŸ•΄ IGI Cybersecurity Introduces CISO Team-as-a-Service πŸ•΄

Service gives customers access to a CISO-led team of practitioners with a variety of skills and expertise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ NSO Group Spyware Used to Breach US State Dept. Phones πŸ•΄

At least nine US State Department employee iPhones were targeted with sophisticated spyware developed by the Israeli firm NSO Group.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-23758 β€Ό

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44352 β€Ό

A Stack-based Buffer Overflow vlnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44347 β€Ό

SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44349 β€Ό

SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.class.php.

πŸ“– Read

via "National Vulnerability Database".