September 9, 2021 at 08:43AM

■□□□□ Israel : A threat actor that goes online with the moniker ‘Sangkancil’ claims to have stolen the personal information of 7 million Israelis. https://securityaffairs.co/wordpress/121984/breaking-news/israelis-data-online.html https://t.me/cKure/9249

September 9, 2021 at 08:41AM

■■■■■ GitHub finds 7 code execution vulnerabilities in ‘tar’ and npm CLI. GitHub security team has identified several high-severity vulnerabilities in npm packages, “tar” and “@npmcli/arborist,” used by npm CLI. The tar package receives 20 million weekly downloads on average, whereas arborist gets downloaded over 300,000 times every week. https://www.bleepingcomputer.com/news/security/github-finds-7-code-execution-vulnerabilities-in-tar-and-npm-cli/ https://t.me/cKure/9247

September 9, 2021 at 08:40AM

■■■■■ A team of academics from universities in Australia , Israel , and the United States has successfully mounted CPU side-channel attacks that recover data from Google Chrome and Chromium-based browsers protected by the Site Isolation feature. https://malware.news/t/new-cpu-side-channel-attack-takes-aim-at-chrome-s-site-isolation-feature/52538 https://t.me/cKure/9246

September 9, 2021 at 12:55AM

■■■■□ Critical Vulnerability in HAProxy (CVE-2021-40346): Integer Overflow Enables HTTP Smuggling https://jfrog.com/blog/critical-vulnerability-in-haproxy-cve-2021-40346-integer-overflow-enables-http-smuggling/ https://t.me/cKure/9244