πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Log4Shell: The Movie… a short, safe visual tour for work and home ⚠

Be happy that your sysadmins are taking one (three, actually!) for the team right now... here's why!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-41561 β€Ό

Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44916 β€Ό

Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44224 β€Ό

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44790 β€Ό

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Healthcare provider Texas ENT alerts 535,000 patients to data breach πŸ—“οΈ

Unauthorized intruder exfiltrated personal data over a six-day period

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Zero Trust Shouldn’t Mean Zero Trust in Employees πŸ•΄

Some think zero trust means you cannot or should not trust employees, an approach that misses the mark and sets up everyone for failure.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-8105 β€Ό

OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit versions prior to 1.0.2.23_6.9V_dev_t2_homekit_RF_2.0.19_s2_kvsABODE oz.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Security researcher earns plaudits after discovering Yandex SSRF flaw πŸ—“οΈ

Russian language search engine has secured its backend infrastructure

πŸ“– Read

via "The Daily Swig".
❌ Third Log4J Bug Can Trigger DoS; Apache Issues Patch ❌

The new Log4j vulnerability is similar to Log4Shell in that it also affects the logging library, but this DoS flaw has to do with Context Map lookups, not JNDI.

πŸ“– Read

via "Threat Post".
πŸ•΄ Four Out of Five Organizations Are Increasing Cybersecurity Budgets for 2022 πŸ•΄

Half of security decision makers also say the cyber skills gap will significantly impact their 2022 strategy, according to new research from Neustar.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Reblaze Appoints New CEO πŸ•΄

Ziv Oren previously held the position of chief operations officer at the company.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Trend Micro Crowns Champions of 2021 Capture the Flag Competition πŸ•΄

Challenges were designed to address critical areas of cybersecurity, including reversing, cloud, IoT, open source intelligence, forensics, and machine learning.

πŸ“– Read

via "Dark Reading".
🦿 Surveillance-for-hire: Are you a target of the booming spy business? 🦿

Meta has exposed and acted against entities that have been spying on people and organizations around the globe. Find out how the threat actors operate and learn what you can do to protect yourself.

πŸ“– Read

via "Tech Republic".
πŸ›  Wapiti Web Application Vulnerability Scanner 3.0.9 πŸ› 

Wapiti is a web application vulnerability scanner. It will scan the web pages of a deployed web application and will fuzz the URL parameters and forms to find common web vulnerabilities.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ SecurityScorecard Research Reveals Cyber Vulnerabilities Pose a Threat to U.S. Maritime Security πŸ•΄

While the shipping industry's cyber posture was better than companies in the Forbes Global 2000, the industry performed lower in key risk group factors.

πŸ“– Read

via "Dark Reading".
πŸ•΄ BlackBerry Launches New Managed Extended Detection and Response (XDR) Service πŸ•΄

Company partners with Exabeam to launch update to its BlackBerry Guard managed detection and response (MDR) service.

πŸ“– Read

via "Dark Reading".
πŸ•΄ SAIC Launches Rugged Apps to Provide Secure Commercial Apps to Government Users πŸ•΄

Rugged Apps ensures mobile apps are NIAP-compliant.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-44675 β€Ό

Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44676 β€Ό

Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44525 β€Ό

Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.

πŸ“– Read

via "National Vulnerability Database".