August 31, 2021 at 04:35AM

■□□□□ Single-factor authentication (SFA) has been added today by the US Cybersecurity and Infrastructure Security Agency (CISA) to a very short list of cybersecurity bad practices it advises against. https://t.me/cKure/9133

August 31, 2021 at 01:16AM

■■□□□ The bug (CVE-2021-33766) is an information-disclosure issue that could reveal victims’ personal information, sensitive company data and more. https://threatpost.com/microsoft-exchange-proxytoken-email/169030/ https://t.me/cKure/9131

August 31, 2021 at 12:03AM

■■■□□ Vulnerabilities Detected in Open Source elFinder File Manager. The five flaws, termed CVE-2021-32682 as a group, have a CVSS score of 9.8, which means they’re highly dangerous. The vulnerability chain impacts elFinder version 2.1.58. https://www.ehackingnews.com/2021/08/vulnerabilities-detected-in-open-source.html https://t.me/cKure/9130

August 30, 2021 at 04:14PM

■■■□□ Trend Micro reported that the theme of commercial spyware Pegasus from NSO Group is used by cybercriminals in phishing campaigns. According to experts, recently the Confucius cybercriminal group conducted a phishing campaign aimed at the Pakistani military. The ma licious campaign was discovered in a broader Trend Micro investigation into Confucius. https://t.me/cKure/9127