πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ That Toy You Got for Christmas Could Be Spying on You ❌

Security flaws in the recently released Fisher-Price Chatter Bluetooth telephone can allow nearby attackers to spy on calls or communicate with children using the device.

πŸ“– Read

via "Threat Post".
🦿 Check for Log4j vulnerabilities with this simple-to-use script 🦿

If you're not certain whether your Java project is free from Log4j vulnerabilities, you should try this easy-to-use scanning tool immediately.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-45814 β€Ό

Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45812 β€Ό

NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45813 β€Ό

SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's credentials theft.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ AV-Comparatives Reveals Results of Long-Term Tests of 19 Leading Endpoint Security Solutions πŸ•΄

The Business Security Test is a comprehensive investigation of corporate endpoint security solutions on the market.

πŸ“– Read

via "Dark Reading".
πŸ•΄ After Google's Landmark Settlement, How Ad Networks Should Tackle Child Privacy πŸ•΄

To comply with the updated COPPA Rule, online ad platforms need to change how they handle viewers who might be children.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Log4j Flaw Will Take Years to be Fully Addressed πŸ•΄

Over 80% of Java packages stored on Maven Central Repository have log4j as an indirect dependency, with most of them burying the vulnerable version five levels deep, says Google's Open Source Insights Team.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-25990 β€Ό

In Ò€œifmeҀ�, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44161 β€Ό

Changing MOTP (Mobile One Time Password) systemÒ€ℒs specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25989 β€Ό

In Ò€œifmeҀ�, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44160 β€Ό

Carinal Tien Hospital Health Report SystemÒ€ℒs login page has improper authentication, a remote attacker can acquire another general userÒ€ℒs privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25991 β€Ό

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to self-ban themself leading to their deactivation from Ifme account and complete loss of admin access in Ifme.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25988 β€Ό

In Ò€œifmeҀ�, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Indian authorities set to tighten data breach laws in 2022 πŸ—“οΈ

Credit card storage rules and 72-hour breach notification deadline due to come into play next year

πŸ“– Read

via "The Daily Swig".
❌ Cryptomining Attack Exploits Docker API Misconfiguration Since 2019 ❌

Campaign exploits misconfigured Docker APIs to gain network entry and ultimately sets up a backdoor on compromised hosts to mine cryptocurrency.

πŸ“– Read

via "Threat Post".
❌ 5 Cybersecurity Trends to Watch in 2022 ❌

Here’s what cybersecurity watchers want infosec pros to know heading into 2022.  

πŸ“– Read

via "Threat Post".
πŸ—“οΈ LastPass quells cyber-attack fears, blames email notification surge on β€˜glitch’ πŸ—“οΈ

Password vault investigation reveals no evidence of credential stuffing activity

πŸ“– Read

via "The Daily Swig".
⚠ SFW! The Top N Cyber­security Stories of 2021 (for small positive integer values of N) ⚠

Happy Holidays! Our Top N stories, all totally SFW!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-38680 β€Ό

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.20 and later

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38687 β€Ό

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later

πŸ“– Read

via "National Vulnerability Database".