πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-3852 β€Ό

growi is vulnerable to Authorization Bypass Through User-Controlled Key

πŸ“– Read

via "National Vulnerability Database".
❌ Phishers Rip Off High-Profile EA Gamers ❌

Electronic Arts blamed β€œhuman error” after attackers compromised customer support and took over and drained some of the top FIFA Ultimate Team player accounts.

πŸ“– Read

via "Threat Post".
🦿 Cisco Talos discovers a new malware campaign using the public cloud to hide its tracks 🦿

The campaign was first detected in October and is using services like AWS and Azure to hide its tracks and evade detection.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Firefox fixes fullscreen notification bypass bug that could have led to convincing phishing campaigns πŸ—“οΈ

Flurry of issues patched in web browser’s latest advisory

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-4080 β€Ό

crater is vulnerable to Unrestricted Upload of File with Dangerous Type

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44648 β€Ό

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44649 β€Ό

Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44650 β€Ό

Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.

πŸ“– Read

via "National Vulnerability Database".
⚠ Home routers with NetUSB support could have critical kernel hole ⚠

Got a router that supports USB access across the network? You might need a kernel update...

πŸ“– Read

via "Naked Security".
⚠ JavaScript developer destroys own projects in supply chain β€œlesson” ⚠

Two popular open source JavaScript packages recently got "hacked" in a symbolic gesture by the original project creator.

πŸ“– Read

via "Naked Security".
πŸ•΄ Patch Management Today: A Risk-Based Strategy to Defeat Cybercriminals πŸ•΄

By combining risk-based vulnerability prioritization and automated patch intelligence, organizations can apply patches based on threat level. Part 2 of 3.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Patch Tuesday: Web security issues in the spotlight in Microsoft’s bumper January update πŸ—“οΈ

β€˜Wormable’ flaw in HTTP Protocol Stack causes concern

πŸ“– Read

via "The Daily Swig".
πŸ›  Proxmark3 4.14831 πŸ› 

This is a custom firmware written for the Proxmark3 device. It extends the currently available firmware. This release is nicknamed Frostbit.

πŸ“– Read

via "Packet Storm Security".
πŸ—“οΈ Cybersecurity conferences 2022: A rundown of online, in person, and β€˜hybrid’ events πŸ—“οΈ

With many events choosing to retain virtual elements forced on them by the pandemic, there’s now an abundance of online content to choose from

πŸ“– Read

via "The Daily Swig".
⚠ Wormable Windows HTTP hole – what you need to know ⚠

One bug in the January 2022 Patch Tuesday list is getting lots of attention: "HTTP Protocol Stack Remote Code Execution Vulnerability".

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-44651 β€Ό

Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44652 β€Ό

Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.

πŸ“– Read

via "National Vulnerability Database".
🦿 US government urges organizations to prepare for Russian-sponsored cyber threats 🦿

Though the feds don't cite any specific threat, a joint advisory from CISA, the FBI and the NSA offers advice on how to detect and mitigate cyberattacks sponsored by Russia.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Critical Infrastructure Security and a Case for Optimism in 2022 πŸ•΄

The new US infrastructure law will fund new action to improve cybersecurity across rail, public transportation, the electric grid, and manufacturing.

πŸ“– Read

via "Dark Reading".
❌ New York AG Warns 17 Firms of Credential Attacks ❌

Sponsored: Password security is highlighted in attorney general warning to New York state businesses.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-0015 β€Ό

A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9.

πŸ“– Read

via "National Vulnerability Database".