πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Why We Need "Developer-First" Application Security πŸ•΄

The way to improve the security of the modern software development life cycle and reduce the number of application-based breaches is to re-center app security around the needs of developers.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Log4j: Security pros call for urgent patch implementation as in-the-wild exploitation continues πŸ—“οΈ

Initial, β€˜incomplete’ patch created path to denial-of-service attacks

πŸ“– Read

via "The Daily Swig".
🦿 Kodachi is the operating system for those who value privacy but don't want to learn Linux 🦿

For anyone looking to gain an extra layer of privacy on a desktop or laptop, Kodachi Linux might be the perfect option. Jack Wallen highlights this live Linux distribution.

πŸ“– Read

via "Tech Republic".
🦿 Just in time for Christmas, Kronos payroll and HR cloud software goes offline due to ransomware 🦿

The attack has led to an outage expected to last weeks, leaving companies scrambling to make payroll with the holidays right around the corner.

πŸ“– Read

via "Tech Republic".
πŸ›  Log4j Recognizer πŸ› 

This utility looks for log4j in the currently running JVM. It is useful for systems that allow plugins to introduce their own jars. Therefore, you can find if someone is using log4j with a dangerous version.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2021-43237 β€Ό

Windows Setup Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43893 β€Ό

Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43227 β€Ό

Storage Spaces Controller Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43235.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43877 β€Ό

ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43907 β€Ό

Visual Studio Code WSL Extension Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41333 β€Ό

Windows Print Spooler Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43892 β€Ό

Microsoft BizTalk ESB Toolkit Spoofing Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43243 β€Ό

VP9 Video Extensions Information Disclosure Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43908 β€Ό

Visual Studio Code Spoofing Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42312 β€Ό

Microsoft Defender for IOT Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43889 β€Ό

Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-42313, CVE-2021-42314, CVE-2021-42315, CVE-2021-43882.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43216 β€Ό

Microsoft Local Security Authority Server (lsasrv) Information Disclosure Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43675 β€Ό

Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42320 β€Ό

Microsoft SharePoint Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-43242.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43256 β€Ό

Microsoft Excel Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43905 β€Ό

Microsoft Office app Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".