πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ HMRC suffered 17 data breaches over 15 months πŸ“’

According to a recent report, the breaches affected more than 3,000 individuals

πŸ“– Read

via "ITPro".
πŸ“’ UK joint committee calls for tougher rules for tech giants πŸ“’

However, IT industry experts suggest Online Safety Bill proposals aren't clear enough for everyday users

πŸ“– Read

via "ITPro".
πŸ“’ Egyptian exiles targeted with Predator spyware resembling NSO Group's Pegasus πŸ“’

A high-profile politician and journalist have been targeted with spyware likely spread using WhatsApp messages

πŸ“– Read

via "ITPro".
πŸ“’ How to turn on Windows Defender πŸ“’

Find out how to switch on Windows Defender in Windows 10 and older versions of the OS

πŸ“– Read

via "ITPro".
πŸ“’ How do hackers choose their targets? πŸ“’

We explore what goes on in the minds of cyber criminals

πŸ“– Read

via "ITPro".
πŸ“’ Skip the three words thing, go straight for the β€˜use a password manager, dammit’ jugular πŸ“’

Why you can do so much better than the three-random-word rule that’s still being churned out by the NCSC

πŸ“– Read

via "ITPro".
πŸ“’ Five things to consider before choosing an MFA solution πŸ“’

Because we all should move on from using β€œpassword” as a password!

πŸ“– Read

via "ITPro".
πŸ“’ UK unveils Β£2.6 billion National Cyber Strategy πŸ“’

The strategy prioritises investing in the UK's cyber skills, improving cyber security responses, and disrupting state-backed cyber attacks

πŸ“– Read

via "ITPro".
πŸ“’ The risks and strategies of using privacy as a business differentiator πŸ“’

With privacy increasingly driving customer decisions, here’s how to make it a differentiator for your business

πŸ“– Read

via "ITPro".
πŸ“’ Log4Shell: New numbers reveal the scale of the critical software exploit πŸ“’

Researchers detail how much the Log4J vulnerability is being exploited and who is being targeted the most

πŸ“– Read

via "ITPro".
β€Ό CVE-2021-4136 β€Ό

vim is vulnerable to Heap-based Buffer Overflow

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44159 β€Ό

4MOSAn GCB DoctorÒ€ℒs file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44162 β€Ό

Chain Sea ai chatbot systemÒ€ℒs specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44163 β€Ό

Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44164 β€Ό

Chain Sea ai chatbot systemÒ€ℒs file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

πŸ“– Read

via "National Vulnerability Database".
⚠ Log4Shell: The Movie… a short, safe visual tour for work and home ⚠

Be happy that your sysadmins are taking one (three, actually!) for the team right now... here's why!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-41561 β€Ό

Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44916 β€Ό

Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44224 β€Ό

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44790 β€Ό

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Healthcare provider Texas ENT alerts 535,000 patients to data breach πŸ—“οΈ

Unauthorized intruder exfiltrated personal data over a six-day period

πŸ“– Read

via "The Daily Swig".