🕴 Privacy and Safety Issues With Facebook's New 'Metaventure' 🕴
📖 Read
via "Dark Reading".
With access to a user's 3D model and full-body digital tracking, attackers can recreate the perfect replica of a C-level executive to trick employees.📖 Read
via "Dark Reading".
Dark Reading
Privacy and Safety Issues With Facebook's New 'Metaventure'
With access to a user's 3D model and full-body digital tracking, attackers can recreate the perfect replica of a C-level executive to trick employees.
🔏 IP Theft: Definition and Examples 🔏
📖 Read
via "".
IP theft can have a long term damaging effects on a company. In this blog, we look at nearly 50 different examples of IP theft to help you better understand the threat.📖 Read
via "".
Digitalguardian
IP Theft: Definition and Examples
IP theft can have long term damaging effects on a company. In this blog, we look at nearly 50 different examples of IP theft to help you better understand the threat.
‼ CVE-2021-42216 ‼
📖 Read
via "National Vulnerability Database".
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.📖 Read
via "National Vulnerability Database".
❌ SAP Kicks Log4Shell Vulnerability Out of 20 Apps ❌
📖 Read
via "Threat Post".
SAP’s still feverishly working to patch another 12 apps vulnerable to the Log4Shell flaw, while its Patch Tuesday release includes 21 other fixes, some rated at 9.9 criticality.📖 Read
via "Threat Post".
Threat Post
SAP Kicks Log4Shell Vulnerability Out of 20 Apps
SAP’s still feverishly working to patch another 12 apps vulnerable to the Log4Shell flaw, while its Patch Tuesday release includes 21 other fixes, some rated at 9.9 criticality.
❌ Malicious Exchange Server Module Hoovers Up Outlook Credentials ❌
📖 Read
via "Threat Post".
"Owowa" stealthily lurks on IIS servers, waiting to harvest successful logins when an Outlook Web Access (OWA) authentication request is made.📖 Read
via "Threat Post".
Threat Post
Malicious Exchange Server Module Hoovers Up Outlook Credentials
"Owowa" stealthily lurks on IIS servers, waiting to harvest successful logins when an Outlook Web Access (OWA) authentication request is made.
🦿 Log4j: How to protect yourself from this security vulnerability 🦿
📖 Read
via "Tech Republic".
As cybercriminals scan for susceptible servers, there are steps you can take to mitigate the Log4j critical vulnerability.📖 Read
via "Tech Republic".
TechRepublic
Log4j: How to protect yourself from this security vulnerability
As cybercriminals scan for susceptible servers, there are steps you can take to mitigate the Log4j critical vulnerability.
🕴 Cybereason Announces Availability of AI-Driven Cybereason XDR and EDR on Google Cloud Marketplace 🕴
📖 Read
via "Dark Reading".
Cloud-native platform automates prevention, detection, and response to cyberattacks.📖 Read
via "Dark Reading".
Dark Reading
Cybereason Announces Availability of AI-Driven Cybereason XDR and EDR on Google Cloud Marketplace
Cloud-native platform automates prevention, detection, and response to cyberattacks.
🕴 Kroll Acquires Security Compass Advisory 🕴
📖 Read
via "Dark Reading".
Combined capabilities will help clients address the growing complexity of securing public, private and hybrid cloud, 5G, IoT, and industrial control systems📖 Read
via "Dark Reading".
Dark Reading
Kroll Acquires Security Compass Advisory
Combined capabilities will help clients address the growing complexity of securing public, private and hybrid cloud, 5G, IoT, and industrial control systems
🕴 Analysis: Log4j Vulnerability Highlights the Value of Defense-in-Depth, Accurate Inventory 🕴
📖 Read
via "Dark Reading".
The early lessons from Log4j indicate that key security principles can help better handle these high-risk software supply chain security incidents if teams have proper support.📖 Read
via "Dark Reading".
Dark Reading
Analysis: Log4j Vulnerability Highlights the Value of Defense-in-Depth, Accurate Inventory
The early lessons from Log4j indicate that key security principles can help better handle these high-risk software supply chain security incidents if teams have proper support.
🕴 Meta Expands Bug-Bounty Program to Include Data Scraping 🕴
📖 Read
via "Dark Reading".
Scraping bugs and scraped databases are two new areas of research for the company's bug-bounty and data-bounty programs.📖 Read
via "Dark Reading".
Dark Reading
Meta Expands Bug-Bounty Program to Include Data Scraping
Scraping bugs and scraped databases are two new areas of research for the company's bug-bounty and data-bounty programs.
🦿 Initial access brokers: How are IABs related to the rise in ransomware attacks? 🦿
📖 Read
via "Tech Republic".
Initial access brokers are cybercriminals who specialize in breaching companies and then selling the access to ransomware attackers. Learn how to protect your business from IABs.📖 Read
via "Tech Republic".
TechRepublic
Initial access brokers: How are IABs related to the rise in ransomware attacks?
Initial access brokers are cybercriminals who specialize in breaching companies and then selling the access to ransomware attackers. Learn how to protect your business from IABs.
‼ CVE-2021-0970 ‼
📖 Read
via "National Vulnerability Database".
In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-196970023📖 Read
via "National Vulnerability Database".
‼ CVE-2021-0931 ‼
📖 Read
via "National Vulnerability Database".
In getAlias of BluetoothDevice.java, there is a possible way to create misleading permission dialogs due to missing data filtering. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-180747689📖 Read
via "National Vulnerability Database".
‼ CVE-2021-1013 ‼
📖 Read
via "National Vulnerability Database".
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186404356📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39652 ‼
📖 Read
via "National Vulnerability Database".
In sec_ts_parsing_cmds of (TBD), there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194499021References: N/A📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39639 ‼
📖 Read
via "National Vulnerability Database".
In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-198291476References: N/A📖 Read
via "National Vulnerability Database".
‼ CVE-2021-1004 ‼
📖 Read
via "National Vulnerability Database".
In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197749180📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39638 ‼
📖 Read
via "National Vulnerability Database".
In periodic_io_work_func of lwis_periodic_io.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195607566References: N/A📖 Read
via "National Vulnerability Database".
‼ CVE-2021-0966 ‼
📖 Read
via "National Vulnerability Database".
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure across Binder transactions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-198346478📖 Read
via "National Vulnerability Database".
‼ CVE-2021-0989 ‼
📖 Read
via "National Vulnerability Database".
In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194105812📖 Read
via "National Vulnerability Database".
‼ CVE-2021-29847 ‼
📖 Read
via "National Vulnerability Database".
BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 205267.📖 Read
via "National Vulnerability Database".