πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Trickbot Injections Get Harder to Detect & Analyze πŸ•΄

The authors of the infamous malware family have added measures for better protecting malicious code injections against inspection and research.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Test Your Team, Not Just Your Disaster Recovery Plan πŸ•΄

Cyberattacks imperil business continuity, but there is a much more common security threat β€” unintentional human error.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-46480 β€Ό

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46477 β€Ό

Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerability can lead to a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44988 β€Ό

Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46481 β€Ό

Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44993 β€Ό

There is an Assertion ''ecma_is_value_boolean (base_value)'' failed at /jerry-core/ecma/operations/ecma-get-put-value.c in Jerryscript 3.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46474 β€Ό

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46483 β€Ό

Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44992 β€Ό

There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44994 β€Ό

There is an Assertion ''JERRY_CONTEXT (jmem_heap_allocated_size) == 0'' failed at /jerry-core/jmem/jmem-heap.c in Jerryscript 3.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46478 β€Ό

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46475 β€Ό

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46482 β€Ό

Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ IT Pro News In Review: UK four-day working week, cyber crime in schools, GDPR fines of €1bn in 2021 πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ“’ NCSC Cyber Essentials overhaul takes effect πŸ“’

Changes to the scope of the government-backed cyber security certification represent the biggest change since the scheme's launch in 2014

πŸ“– Read

via "ITPro".
πŸ“’ Crypto.com confirms $34 million hack caused by 2FA bypass exploit πŸ“’

The cryptocurrency exchange previously denied that any customers lost funds despite numerous reports from customers and analysts

πŸ“– Read

via "ITPro".
πŸ“’ Datto's cyber security team catalysed recent Infocyte acquisition πŸ“’

Datto said it will take its time integrating Infocyte's endpoint and cloud environment security technology

πŸ“– Read

via "ITPro".
πŸ“’ UK Online Safety Bill a "missed opportunity", MPs claim πŸ“’

A DCMS report says the "unclear" draft legislation doesn't do enough to tackle child abuse and violence against women and girls

πŸ“– Read

via "ITPro".
πŸ“’ Openreach offers Β£20,000 reward for information on stolen copper cables πŸ“’

Openreach head of Security Services Richard Ginnaw said that the thefts had β€œseverely impacted" the day-to-day lives of people in Cambridgeshire

πŸ“– Read

via "ITPro".
β€Ό CVE-2021-45340 β€Ό

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

πŸ“– Read

via "National Vulnerability Database".