πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Oracle's massive advertising database operates without user consent, lawsuit claims πŸ“’

Rights organisers have accused Oracle of collecting an undue level of sensitive data to identify consumers online

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft 365 business users targeted with new DocuSign phishing scam πŸ“’

Threat actors are using fake login forms to trick users into changing their payment details

πŸ“– Read

via "ITPro".
πŸ“’ India forced Twitter to hire a government agent, whistleblower claims πŸ“’

Former employee Peiter Zatko says the social media platform gave the agent direct unsupervised access to the company’s systems and user data

πŸ“– Read

via "ITPro".
πŸ“’ CMS Distribution partners with GuardYoo for new Attack Surface Management offering πŸ“’

The hosted service has been designed to strengthen resilience against vulnerabilities without sacrificing growth, company says

πŸ“– Read

via "ITPro".
πŸ“’ Digital transformation giant Orion Innovation hit by LockBit ransomware, hacker group claims πŸ“’

The company has a star-studded client list that includes some of the biggest sports organisations in the world and an assortment of tech behemoths

πŸ“– Read

via "ITPro".
πŸ“’ LastPass breach: CEO says 'no evidence' of customer data being stolen πŸ“’

The company said the incident was confined to a single developer account and its associated environment

πŸ“– Read

via "ITPro".
πŸ“’ What is a 502 bad gateway and how do you fix it? πŸ“’

We explain what this networking error means for users and website owners

πŸ“– Read

via "ITPro".
πŸ€”1
πŸ“’ NEC and Fortinet partner to deliver high-performance security for 5G networks πŸ“’

The carrier solution will ensure end-to-end security while CSPs contend with increased traffic

πŸ“– Read

via "ITPro".
πŸ“’ Block accused of woefully mishandling data breach affecting 8.2 million users πŸ“’

Class-action lawsuit claims the company took too long to inform customers and failed to provide a sufficient explanation for the breach

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ More than 130 organisations affected by β€œinexperienced” Twilio hackers πŸ“’

A thorough investigation revealed sophisticated methods coupled with relatively unsophisticated tooling

πŸ“– Read

via "ITPro".
πŸ•΄ LastPass Suffers Data Breach, Source Code Stolen πŸ•΄

Researchers warned that cyberattackers will be probing the code for weaknesses to exploit later.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-3688 β€Ό

A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3859 β€Ό

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20260 β€Ό

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4215 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25625 β€Ό

A malicious unauthorized PAM user can access the administration configuration data and change the values.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3427 β€Ό

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3754 β€Ό

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3651 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3574 β€Ό

A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.

πŸ“– Read

via "National Vulnerability Database".