18 March 2021
?
13:32
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-24137 β€Ό

Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24124 β€Ό

Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is shown could lead to privileged escalation.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-21625 β€Ό

Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins in some circumstances.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24129 β€Ό

Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Scripting (XSS) vulnerabilities allowing low-privileged users (Contributor+) to inject arbitrary JavaScript code or HTML in posts where the Themify Custom Panel is embedded, which could lead to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24134 β€Ό

Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24136 β€Ό

Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24139 β€Ό

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24128 β€Ό

Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24130 β€Ό

Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24149 β€Ό

Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24127 β€Ό

Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-26237 β€Ό

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24146 β€Ό

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24125 β€Ό

Unvalidated input in the Contact Form Submissions WordPress plugin, versions 1.6.4 and before, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privilege user (admin+)

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24143 β€Ό

Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-24132 β€Ό

The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-26935 β€Ό

In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-26233 β€Ό

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

πŸ“– Read

via "National Vulnerability Database".
?
14:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Beware the Package Typosquatting Supply Chain Attack πŸ•΄

Attackers are mimicking the names of existing packages on public registries in hopes that users or developers will accidentally download these malicious packages instead of legitimate ones.

πŸ“– Read

via "Dark Reading".
?
14:52
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ FBI: Business Email Compromise Cost $1.8B in 2020 πŸ•΄

The Internet Crime Complaint Center received a record 791,790 complaints last year, with reported losses exceeding $4.1 billion.

πŸ“– Read

via "Dark Reading".
14:57
🦿 How cybercriminals are targeting US taxpayers as tax season approaches 🦿

The latest scams use phishing emails to deliver remote access trojans to control a victim's computer and steal sensitive data, says Cybereason.

πŸ“– Read

via "Tech Republic".
?
15:32
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-28796 β€Ό

Increments Qiita::Markdown before 0.33.0 allows XSS in transformers.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2021-26216 β€Ό

SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2020-27827 β€Ό

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2021-28145 β€Ό

Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2020-26155 β€Ό

Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak permissions, could enable an attacker to perform a DLL hijacking attack.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2021-28790 β€Ό

The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftlint.path configuration value that triggers execution upon opening the workspace.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2021-28791 β€Ό

The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftformat.path configuration value that triggers execution upon opening the workspace.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2021-21383 β€Ό

Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scripting through mustache expressions in code blocks. This vulnerability exists due to mustache expressions being parsed by Vue during content injection even though it is contained within a `<pre>` element. By creating a crafted wiki page, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the page is viewed by other users. For an example see referenced GitHub Security Advisory. Commit 5ffa189383dd716f12b56b8cae2ba0d075996cf1 fixes this vulnerability by adding the v-pre directive to all `<pre>` tags during the render.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2021-28789 β€Ό

The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted apple-swift-format.path configuration value that triggers execution upon opening the workspace.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2021-26215 β€Ό

SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2021-28794 β€Ό

The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath.

πŸ“– Read

via "National Vulnerability Database".
15:32
β€Ό CVE-2021-28792 β€Ό

The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted sourcekit-lsp.serverPath, swift.languageServerPath, swift.path.sourcekite, swift.path.sourcekiteDockerMode, swift.path.swift_driver_bin, or swift.path.shell configuration value that triggers execution upon opening the workspace.

πŸ“– Read

via "National Vulnerability Database".
?
15:52
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ New CopperStealer Malware Hijacks Social Media Accounts πŸ•΄

Proofpoint researchers say it steals logins and spreads more malware.

πŸ“– Read

via "Dark Reading".
?
16:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Women's History Month: Making Mentorship Meaningful πŸ•΄

This month is a perfect opportunity for us to take a step back and think about what role we want to play as women in the technology sector.

πŸ“– Read

via "Dark Reading".
?
17:05
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Trojanized Xcode Project Slips MacOS Malware to Apple Developers ❌

In a new campaign, threat actors are bundling macOS malware in trojanized Apple Xcode developer projects.

πŸ“– Read

via "Threat Post".
?
17:32
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2019-14903 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2020-35492 β€Ό

A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2019-14850 β€Ό

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2021-27656 β€Ό

A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2021-1287 β€Ό

A vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition on the affected device.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2019-3867 β€Ό

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2019-14908 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2020-14516 β€Ό

In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2021-22665 β€Ό

Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and complete control of the system.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2021-28160 β€Ό

Stored XSS on Acexy (BoyaMicro) Wireless-N WiFi Repeater 28.08.06.1 version 1.0 devices can occur via a malformed SSID field during scanning for nearby access points, which also occurs when a device's user visits the Repeater Wizard web management section. This enables an attacker to steal LAN credentials without being connected to the device.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2019-14848 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
17:35
❌ Fiserv Forgets to Buy Domain It Used as System Default ❌

Fintech security provider Fiserv acknowledges it used unregistered domain as default email.

πŸ“– Read

via "Threat Post".
?
18:52
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Facebook Expands Security Key Support to iOS & Android πŸ•΄

Facebook's announcement arrives the same week Twitter enabled support for multiple security keys on user accounts.

πŸ“– Read

via "Dark Reading".
?
19:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Tech Vendors' Lack of Security Transparency Worries Firms πŸ•΄

A majority of firms say they're more likely to buy from suppliers that are open about security issues -- yet that sentiment isn't necessarily reflected in the technology providers they're currently working with.

πŸ“– Read

via "Dark Reading".
19:37
β€Ό CVE-2021-3416 β€Ό

A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-25764 β€Ό

In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2020-26886 β€Ό

Softaculous before 5.5.7 is affected by a code execution vulnerability because of External Initialization of Trusted Variables or Data Stores. This leads to privilege escalation on the local host.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2019-14851 β€Ό

A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2019-14852 β€Ό

A flaw was found in 3scaleÒ€ℒs APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information. Version shipped in Red Hat 3scale API Management Platform is vulnerable to this issue.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2020-9367 β€Ό

The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code, leading to an escalation of privilege to NT AUTHORITY\SYSTEM.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2020-36144 β€Ό

Redash 8.0.0 is affected by LDAP Injection. There is an authentication bypass and information leak through the crafting of special queries, escaping the provided template because the ldap_user = auth_ldap_user(request.form["email"], request.form["password"]) auth_ldap_user(username, password) settings.LDAP_SEARCH_TEMPLATE % {"username": username} code lacks sanitization.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2020-26797 β€Ό

Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-27358 β€Ό

The snapshot feature in Grafana before 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

πŸ“– Read

via "National Vulnerability Database".
?
21:32
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-27436 β€Ό

WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the userÒ€ℒs cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser actions.

πŸ“– Read

via "National Vulnerability Database".
19 March 2021
?
02:32
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-25293 β€Ό

An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.

πŸ“– Read

via "National Vulnerability Database".
02:32
β€Ό CVE-2021-3327 β€Ό

Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter.

πŸ“– Read

via "National Vulnerability Database".
02:32
β€Ό CVE-2021-21384 β€Ό

shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a into the payload. For an example see the referenced GitHub Security Advisory. The problem has been patched in version 1.1.3. No further changes are required.

πŸ“– Read

via "National Vulnerability Database".
02:32
β€Ό CVE-2021-25290 β€Ό

An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.

πŸ“– Read

via "National Vulnerability Database".
02:32
β€Ό CVE-2020-6577 β€Ό

The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.

πŸ“– Read

via "National Vulnerability Database".
02:32
β€Ό CVE-2021-28653 β€Ό

The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave support but lacks biometric authentication hardware.

πŸ“– Read

via "National Vulnerability Database".
02:32
β€Ό CVE-2021-26275 β€Ό

** UNSUPPORTED WHEN ASSIGNED ** The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repository has been intentionally deleted.

πŸ“– Read

via "National Vulnerability Database".
02:32
β€Ό CVE-2021-28126 β€Ό

index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability

πŸ“– Read

via "National Vulnerability Database".
02:32
β€Ό CVE-2020-6578 β€Ό

Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.

πŸ“– Read

via "National Vulnerability Database".
02:32
β€Ό CVE-2021-25292 β€Ό

An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.

πŸ“– Read

via "National Vulnerability Database".
02:33
β€Ό CVE-2021-25289 β€Ό

An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.

πŸ“– Read

via "National Vulnerability Database".
02:33
β€Ό CVE-2021-27221 β€Ό

** DISPUTED ** MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work.

πŸ“– Read

via "National Vulnerability Database".
02:33
β€Ό CVE-2021-28110 β€Ό

/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.

πŸ“– Read

via "National Vulnerability Database".
02:33
β€Ό CVE-2021-27928 β€Ό

A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.

πŸ“– Read

via "National Vulnerability Database".
02:33
β€Ό CVE-2021-25291 β€Ό

An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.

πŸ“– Read

via "National Vulnerability Database".
02:33
β€Ό CVE-2021-28109 β€Ό

TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
?
07:57
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Want to be an ethical hacker? Take these cybersecurity courses 🦿

In these 18 online training courses on ethical hacking, cybersecurity pros will teach you about creating projects with Python, bug bounty hunting, Kali Linux hacker tools and much more.

πŸ“– Read

via "Tech Republic".
?
12:23
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Russian Man Pleads Guilty in Thwarted Tesla Hack πŸ•΄

Egor Kriuchkov will be sentenced in May on conspiracy charge

πŸ“– Read

via "Dark Reading".
12:27
🦿 Business email compromise scams proved costly to victims in 2020 🦿

The FBI received more than 19,000 complaints of business email compromises last year, costing victims around $1.8 billion.

πŸ“– Read

via "Tech Republic".
12:36
❌ Bogus Android Clubhouse App Drops Credential-Swiping Malware ❌

The malicious app spreads the BlackRock malware, which steals credentials from 458 services - including Twitter, WhatsApp, Facebook and Amazon.

πŸ“– Read

via "Threat Post".
?
12:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ SolarWinds-Linked Attackers Target Microsoft 365 Mailboxes πŸ•΄

Researchers observe attackers altering mailbox folders to assign read-only permissions to any authenticated user on a target machine.

πŸ“– Read

via "Dark Reading".
?
13:33
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-27506 β€Ό

In Stormshield Network Security (SNS) 1.0 through 4.2.0, the parsing of some malformed files can lead to the crash of ClamAV service causing a Denial of Service.

πŸ“– Read

via "National Vulnerability Database".
13:45
πŸ” Friday Five 3/19 πŸ”

Stolen phone access, cybersecurity in national security, and the theft of NFTs - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "Digital Guardian".
?
15:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How to use semanage and avoid disabling SELinux 🦿

Jack Wallen introduces you to three semanage commands that will help make dealing with SELinux considerably easier.

πŸ“– Read

via "Tech Republic".
15:33
β€Ό CVE-2020-4635 β€Ό

IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames.

πŸ“– Read

via "National Vulnerability Database".
15:33
β€Ό CVE-2021-25277 β€Ό

FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component.

πŸ“– Read

via "National Vulnerability Database".
15:33
β€Ό CVE-2021-25278 β€Ό

FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template Editor.

πŸ“– Read

via "National Vulnerability Database".
15:33
β€Ό CVE-2021-27906 β€Ό

A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

πŸ“– Read

via "National Vulnerability Database".
15:33
β€Ό CVE-2021-27807 β€Ό

A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

πŸ“– Read

via "National Vulnerability Database".
15:33
β€Ό CVE-2021-21390 β€Ό

MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-17T02-33-02Z, there is a vulnerability which enables MITM modification of request bodies that are meant to have integrity guaranteed by chunk signatures. In a PUT request using aws-chunked encoding, MinIO ordinarily verifies signatures at the end of a chunk. This check can be skipped if the client sends a false chunk size that is much greater than the actual data sent: the server accepts and completes the request without ever reaching the end of the chunk + thereby without ever checking the chunk signature. This is fixed in version RELEASE.2021-03-17T02-33-02Z. As a workaround one can avoid using "aws-chunked" encoding-based chunk signature upload requests instead use TLS. MinIO SDKs automatically disable chunked encoding signature when the server endpoint is configured with TLS.

πŸ“– Read

via "National Vulnerability Database".
15:33
β€Ό CVE-2021-21387 β€Ό

Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.0 and before 2.3.0 there was a set of vulnerabilities causing inadequate encryption strength. Part of the secret identity key was disclosed by the fingerprint used for connection. Additionally, the safety number was improperly calculated. It was computed using part of one of the public identity keys instead of being derived from both public identity keys. This caused issues in computing safety numbers which would potentially be exploitable in the real world. Additionally there was inadequate encryption strength due to use of 1024-bit DSA keys. These issues are all fixed in version 2.3.0.

πŸ“– Read

via "National Vulnerability Database".
15:36
❌ Office 365 Phishing Attack Targets Financial Execs ❌

Attackers move on new CEOs, using transition confusion to harvest Microsoft credentials.

πŸ“– Read

via "Threat Post".
?
15:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Verkada Attacker Charged with Wire Fraud, Conspiracy in US πŸ•΄

Swiss national Till Kottmann and co-conspirators are accused of breaking into dozens of US companies and government entities.

πŸ“– Read

via "Dark Reading".
?
17:33
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-20077 β€Ό

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

πŸ“– Read

via "National Vulnerability Database".
17:33
β€Ό CVE-2021-27520 β€Ό

A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.

πŸ“– Read

via "National Vulnerability Database".
17:33
β€Ό CVE-2021-27519 β€Ό

A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.

πŸ“– Read

via "National Vulnerability Database".
17:33
β€Ό CVE-2021-26990 β€Ό

Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.

πŸ“– Read

via "National Vulnerability Database".
17:33
β€Ό CVE-2019-10127 β€Ό

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. An attacker having only the unprivileged Windows account can read arbitrary data directory files, essentially bypassing database-imposed read access limitations. An attacker having only the unprivileged Windows account can also delete certain data directory files.

πŸ“– Read

via "National Vulnerability Database".
17:33
β€Ό CVE-2021-26991 β€Ό

Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow a remote attacker to interact with Cloud Manager.

πŸ“– Read

via "National Vulnerability Database".
17:33
β€Ό CVE-2021-26992 β€Ό

Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
?
18:06
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Critical F5 BIG-IP Flaw Now Under Active Attack ❌

Researchers are reporting mass scanning for – and in-the-wild exploitation of – a critical-severity flaw in the F5 BIG-IP and BIG-IQ enterprise networking infrastructure.

πŸ“– Read

via "Threat Post".
?
18:23
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ New Malware Hidden in Apple IDE Targets macOS Developers πŸ•΄

XcodeSpy is latest example of growing attacks on software supply chain.

πŸ“– Read

via "Dark Reading".
18:27
🦿 PS5 phishing scam baits gamers with promise of free console 🦿

Scammers are taking advantage of a shortage of Sony PlayStation 5 consoles to try to hoodwink people eager to snag one, says Kaspersky.

πŸ“– Read

via "Tech Republic".
?
19:33
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2019-10151 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
19:33
β€Ό CVE-2019-10128 β€Ό

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to read arbitrary data directory files, essentially bypassing database-imposed read access limitations. In plausible non-default configurations, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
19:33
β€Ό CVE-2019-10200 β€Ό

A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials for the master AWS IAM role, allowing management access to AWS resources. With access to the security credentials, the user then has access to the entire infrastructure. Impact to data and system availability is high.

πŸ“– Read

via "National Vulnerability Database".
19:33
β€Ό CVE-2019-14828 β€Ό

A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role.

πŸ“– Read

via "National Vulnerability Database".
19:33
β€Ό CVE-2019-10196 β€Ό

A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.

πŸ“– Read

via "National Vulnerability Database".
19:33
β€Ό CVE-2019-14830 β€Ό

A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app").

πŸ“– Read

via "National Vulnerability Database".
19:33
β€Ό CVE-2019-10225 β€Ό

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service, gaining access to read, and modify files.

πŸ“– Read

via "National Vulnerability Database".
19:33
β€Ό CVE-2021-21267 β€Ό

Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `a@0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.`) will freeze the program or web browser page executing the code. This affects any current schema-inspector users using any version to validate email addresses. Users who do not do email validation, and instead do other types of validation (like string min or max length, etc), are not affected. Users should upgrade to version 2.0.0, which uses a regex expression that isn't vulnerable to ReDoS.

πŸ“– Read

via "National Vulnerability Database".
19:33
β€Ό CVE-2019-14829 β€Ό

A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.

πŸ“– Read

via "National Vulnerability Database".
19:33
β€Ό CVE-2019-14831 β€Ό

A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the forum's subscribe link contained an open redirect.

πŸ“– Read

via "National Vulnerability Database".
20 March 2021
?
21:35
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-27171 β€Ό

An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-10d2bb2e6b1d.

πŸ“– Read

via "National Vulnerability Database".
21:35
β€Ό CVE-2020-27170 β€Ό

An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.

πŸ“– Read

via "National Vulnerability Database".
21 March 2021
?
07:35
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-28961 β€Ό

applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.

πŸ“– Read

via "National Vulnerability Database".
07:35
β€Ό CVE-2021-28957 β€Ό

lxml 4.6.2 places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute.

πŸ“– Read

via "National Vulnerability Database".
07:35
β€Ό CVE-2021-28954 β€Ό

In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository.

πŸ“– Read

via "National Vulnerability Database".
07:35
β€Ό CVE-2021-28953 β€Ό

The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository.

πŸ“– Read

via "National Vulnerability Database".
?
19:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-13963 β€Ό

SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).

πŸ“– Read

via "National Vulnerability Database".
22 March 2021
?
11:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-26295 β€Ό

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

πŸ“– Read

via "National Vulnerability Database".
11:37
β€Ό CVE-2020-28501 β€Ό

This affects the package es6-crawler-detect before 3.1.3. No limitation of user agent string length supplied to regex operators.

πŸ“– Read

via "National Vulnerability Database".
?
12:55
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ Instagram scams and how to avoid them ⚠

Don't get taken for a sucker on social media! Here are our top tips to protect you from Instagram scams...

πŸ“– Read

via "Naked Security".
12:55
πŸ•΄ The Edge Pro Tip: The Feds Are Your Friends πŸ•΄

Here's what to expect when you report an insider incident to the FBI.

πŸ“– Read

via "Dark Reading".
12:55
πŸ•΄ 3 Classes of Account Fraud That Can Cost Your Company Big Time πŸ•΄



πŸ“– Read

via "Dark Reading".
13:01
🦿 Cloudflare introduces SD-WAN- and firewall-as-a-service offerings 🦿

In a bid to replace MPLS circuits and SD-WAN appliances, Cloudflare has introduced Magic WAN and Magic Firewall and partnerships with VMware, Aruba, Digital Realty, CoreSite and EdgeConneX.

πŸ“– Read

via "Tech Republic".
13:09
❌ Adobe Fixes Critical ColdFusion Flaw in Emergency Update ❌

Attackers can leverage the critical Adobe ColdFusion flaw to launch arbitrary code execution attacks.

πŸ“– Read

via "Threat Post".
?
13:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-28147 β€Ό

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2021-28148 β€Ό

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2021-27962 β€Ό

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2021-28146 β€Ό

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2021-27308 β€Ό

A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.

πŸ“– Read

via "National Vulnerability Database".
?
14:25
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Top 3 Cybersecurity Lessons Learned From the Pandemic πŸ•΄

Defending an enterprise of fully remote employees and their devices at this scale and speed had never been done before. Now, we do it every day.

πŸ“– Read

via "Dark Reading".
?
14:55
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ Naked Security Live – β€œXcodeSpy” takes aim at Mac and iOS developers ⚠

New episode - watch now!

πŸ“– Read

via "Naked Security".
?
15:25
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Qualys CEO Courtot Departs for Health Reasons πŸ•΄

The well-known security industry entrepreneur initially took a leave of absence in February.

πŸ“– Read

via "Dark Reading".
15:37
β€Ό CVE-2021-27595 β€Ό

When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

πŸ“– Read

via "National Vulnerability Database".
15:37
β€Ό CVE-2021-28971 β€Ό

In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.

πŸ“– Read

via "National Vulnerability Database".
15:37
β€Ό CVE-2021-27593 β€Ό

When a user opens manipulated Graphics Interchange Format (.GIF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

πŸ“– Read

via "National Vulnerability Database".
15:37
β€Ό CVE-2021-28968 β€Ό

An issue was discovered in PunBB before 1.4.6. An XSS vulnerability in the [email] BBcode tag allows (with authentication) injecting arbitrary JavaScript into any forum message.

πŸ“– Read

via "National Vulnerability Database".
15:37
β€Ό CVE-2021-27596 β€Ό

When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

πŸ“– Read

via "National Vulnerability Database".
15:37
β€Ό CVE-2021-27594 β€Ό

When a user opens manipulated Windows Bitmap (.BMP) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

πŸ“– Read

via "National Vulnerability Database".
15:37
β€Ό CVE-2020-4882 β€Ό

IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 190852.

πŸ“– Read

via "National Vulnerability Database".
15:37
β€Ό CVE-2021-28972 β€Ό

In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.

πŸ“– Read

via "National Vulnerability Database".
?
16:09
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Critical Security Bugs Fixed in Virtual Learning Software ❌

Remote ed software bugs give attackers wide access student computers, data.

πŸ“– Read

via "Threat Post".
?
17:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ” U.S. Indicts Swiss Hacker Responsible for Security Camera Hack, Data Theft πŸ”

While only 21, the Swiss "hacktivist" has hacked dozens of companies and published data like source code, files, and other proprietary information online.

πŸ“– Read

via "Digital Guardian".
17:25
πŸ•΄ CSA & ISACA Team Up on Cloud Auditing Certificate πŸ•΄

The Certificate of Cloud Auditing Knowledge aims to fill a gap in the market for cloud IT auditing as more organizations work in cloud environments.

πŸ“– Read

via "Dark Reading".
17:37
β€Ό CVE-2021-22309 β€Ό

There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions include:USG9500 versions V500R001C30SPC200, V500R001C60SPC500,V500R005C00SPC200;USG9520 versions V500R005C00;USG9560 versions V500R005C00;USG9580 versions V500R005C00.

πŸ“– Read

via "National Vulnerability Database".
17:37
β€Ό CVE-2021-22310 β€Ό

There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected product versions include: NIP6300 versions V500R001C00,V500R001C20,V500R001C30;NIP6600 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6300 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6500 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6600 versions V500R001C00,V500R001C20,V500R001C30,V500R001C50,V500R001C60,V500R001C80;USG9500 versions V500R005C00,V500R005C10.

πŸ“– Read

via "National Vulnerability Database".
17:37
β€Ό CVE-2020-9212 β€Ό

There is a vulnerability in some version of USG9500 that the device improperly handles the information when a user logs in to device. The attacker can exploit the vulnerability to perform some operation and can get information and cause information leak.

πŸ“– Read

via "National Vulnerability Database".
17:37
β€Ό CVE-2020-9206 β€Ό

The eUDC660 product has a resource management vulnerability. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the device, as a result, the key file can be obtained and data can be decrypted, affecting confidentiality, integrity, and availability of the device.

πŸ“– Read

via "National Vulnerability Database".
17:37
β€Ό CVE-2020-9213 β€Ό

There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft many specific packets. Successful exploit may cause some services to be abnormal. Affected products include some versions of NGFW Module, NIP6300, NIP6600, NIP6800, Secospace USG6300, Secospace USG6500, Secospace USG6600 and SG9500.

πŸ“– Read

via "National Vulnerability Database".
17:37
β€Ό CVE-2021-22311 β€Ό

There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do certain operations with improper permissions. Affected product versions include: ManageOne versions 8.0.0, 8.0.1.

πŸ“– Read

via "National Vulnerability Database".
17:37
β€Ό CVE-2021-26578 β€Ό

A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection.

πŸ“– Read

via "National Vulnerability Database".
17:37
β€Ό CVE-2021-22320 β€Ό

There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affected module. This can lead to denial of service. Affected product include some versions of IPS Module, NGFW Module, NIP6600, NIP6800, Secospace USG6300, Secospace USG6500 and Secospace USG6600.

πŸ“– Read

via "National Vulnerability Database".
17:37
β€Ό CVE-2021-25265 β€Ό

A malicious website could execute code remotely in Sophos Connect Client before version 2.1.

πŸ“– Read

via "National Vulnerability Database".
?
18:09
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ CISA Warns of Security Flaws in GE Power Management Devices ❌

The flaws could allow an attacker to access sensitive information, reboot the UR, gain privileged access, or cause a denial-of-service condition.

πŸ“– Read

via "Threat Post".
?
18:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 7 expert tips on recruiting cybersecurity pros 🦿

HR and recruiting experts offer unique ways to find and hire cybersecurity talent.

πŸ“– Read

via "Tech Republic".
?
19:25
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Acer Reportedly Hit With $50M Ransomware Attack πŸ•΄

Reports say a ransomware gang has given Acer until March 28 to pay, or it will double the ransom amount.

πŸ“– Read

via "Dark Reading".
19:37
β€Ό CVE-2021-25918 β€Ό

In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-22314 β€Ό

There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-25919 β€Ό

In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-25921 β€Ό

In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker could lure an admin to enter a malicious payload and by that initiate the exploit.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-25917 β€Ό

In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-25922 β€Ό

In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-22321 β€Ό

There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2700, S5700, S6700 , S7700, S9700, Secospace USG6300, Secospace USG6500, Secospace USG6600 and USG9500.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-25920 β€Ό

In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.

πŸ“– Read

via "National Vulnerability Database".
?
19:55
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Researchers Discover Two Dozen Malicious Chrome Extensions πŸ•΄

Extensions are being used to serve up unwanted adds, steal data, and divert users to malicious sites, Cato Networks says.

πŸ“– Read

via "Dark Reading".
23 March 2021
?
02:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-21341 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:37
β€Ό CVE-2021-21346 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:37
β€Ό CVE-2021-21338 β€Ό

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handling is susceptible to open redirection which allows attackers redirecting to arbitrary content, and conducting phishing attacks. No authentication is required in order to exploit this vulnerability. This is fixed in versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.

πŸ“– Read

via "National Vulnerability Database".
02:37
β€Ό CVE-2021-21340 β€Ό

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content gets previewed. A valid backend user account is needed to exploit this vulnerability. This is fixed in versions 10.4.14, 11.1.1 .

πŸ“– Read

via "National Vulnerability Database".
02:37
β€Ό CVE-2021-21349 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:37
β€Ό CVE-2021-21351 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:37
β€Ό CVE-2021-21350 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:37
β€Ό CVE-2021-21355 β€Ό

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with arbitrary file extensions - however, default _fileDenyPattern_ successfully blocked files like _.htaccess_ or _malicious.php_. Besides that, _UploadedFileReferenceConverter_ transforming uploaded files into proper FileReference domain model objects handles possible file uploads for other extensions as well - given those extensions use the Extbase MVC framework, make use of FileReference items in their direct or inherited domain model definitions and did not implement their own type converter. In case this scenario applies, _UploadedFileReferenceConverter_ accepts any file mime-type and persists files in the default location. In any way, uploaded files are placed in the default location _/fileadmin/user_upload/_, in most scenarios keeping the submitted filename - which allows attackers to directly reference files, or even correctly guess filenames used by other individuals, disclosing this information. No authentication is required to exploit this vulnerability. This is fixed in versions 8.7.40, 9.5.25, 10.4.14, 11.1.1.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21343 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the processed input stream and replace or inject objects, that result in the deletion of a file on the local host. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21357 β€Ό

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass restrictions of predefined options and submit arbitrary data in the Form Designer backend module of the Form Framework. In the default configuration of the Form Framework this allows attackers to explicitly allow arbitrary mime-types for file uploads - however, default _fileDenyPattern_ successfully blocked files like _.htaccess_ or _malicious.php_. Besides that, attackers can persist those files in any writable directory of the corresponding TYPO3 installation. A valid backend user account with access to the form module is needed to exploit this vulnerability. This is fixed in versions 8.7.40, 9.5.25, 10.4.14, 11.1.1.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21342 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the processed input stream and replace or inject objects, that result in a server-side forgery request. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21359 β€Ό

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as error message from another page. This leads to a scenario in which the application is calling itself recursively - amplifying the impact of the initial attack until the limits of the web server are exceeded. This is fixed in versions 9.5.25, 10.4.14, 11.1.1.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21370 β€Ό

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced items get previewed in the page module. A valid backend user account is needed to exploit this vulnerability. This is fixed in versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21348 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21347 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21339 β€Ό

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system. This is fixed in versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21358 β€Ό

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user account with access to the form module is needed to exploit this vulnerability. This is fixed in versions 10.4.14, 11.1.1.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21344 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
02:38
β€Ό CVE-2021-21345 β€Ό

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

πŸ“– Read

via "National Vulnerability Database".
?
07:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-29077 β€Ό

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29067 β€Ό

Certain NETGEAR devices are affected by authentication bypass. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29079 β€Ό

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29076 β€Ό

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29068 β€Ό

Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before 1.0.4.98, R6400v2 before 1.0.4.98, R7000 before 1.0.11.106, R6900P before 1.3.2.124, R7000P before 1.3.2.124, R7900 before 1.0.4.26, R7850 before 1.0.5.60, R8000 before 1.0.4.58, RS400 before 1.5.0.48, R6400 before 1.0.1.62, R6700 before 1.0.2.16, R6900 before 1.0.2.16, MK60 before 1.0.5.102, MR60 before 1.0.5.102, MS60 before 1.0.5.102, CBR40 before 2.5.0.10, R8000P before 1.4.1.62, R7960P before 1.4.1.62, R7900P before 1.4.1.62, RAX15 before 1.0.1.64, RAX20 before 1.0.1.64, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RAX200 before 1.0.2.102, RAX45 before 1.0.2.64, RAX50 before 1.0.2.64, EX7500 before 1.0.0.68, EAX80 before 1.0.1.62, EAX20 before 1.0.0.36, RBK752 before 3.2.16.6, RBK753 before 3.2.16.6, RBK753S before 3.2.16.6, RBK754 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBK853 before 3.2.16.6, RBK854 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RBR840 before 3.2.16.6, RBS840 before 3.2.16.6, R6120 before 1.0.0.70, R6220 before 1.1.0.100, R6230 before 1.1.0.100, R6260 before 1.1.0.76, R6850 before 1.1.0.76, R6350 before 1.1.0.76, R6330 before 1.1.0.76, D7800 before 1.0.1.58, RBK50 before 2.6.1.40, RBR50 before 2.6.1.40, RBS50 before 2.6.1.40, RBK40 before 2.6.1.36, RBR40 before 2.6.1.36, RBS40 before 2.6.1.38, RBK23 before 2.6.1.36, RBR20 before 2.6.1.38, RBS20 before 2.6.1.38, RBK12 before 2.6.1.44, RBK13 before 2.6.1.44, RBK14 before 2.6.1.44, RBK15 before 2.6.1.44, RBR10 before 2.6.1.44, RBS10 before 2.6.1.44, R6800 before 1.2.0.72, R6900v2 before 1.2.0.72, R6700v2 before 1.2.0.72, R7200 before 1.2.0.72, R7350 before 1.2.0.72, R7400 before 1.2.0.72, R7450 before 1.2.0.72, AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, R7800 before 1.0.2.74, R8900 before 1.0.5.24, R9000 before 1.0.5.24, RAX120 before 1.0.1.136, XR450 before 2.3.2.66, XR500 before 2.3.2.66, XR700 before 1.0.1.34, and XR300 before 1.0.3.50.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29080 β€Ό

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29071 β€Ό

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBR752 before 3.2.17.12, RBR753 before 3.2.17.12, RBR753S before 3.2.17.12, RBR754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29082 β€Ό

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBW30 before 2.6.1.4, RBS40V before 2.6.1.4, RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBK754 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBK854 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29081 β€Ό

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects RBW30 before 2.6.2.2, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29069 β€Ό

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR450 before 2.3.2.114, XR500 before 2.3.2.114, and WNR2000v5 before 1.0.0.76.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29066 β€Ό

Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29070 β€Ό

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29065 β€Ό

NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29073 β€Ό

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R8000P before 1.4.1.66, MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before 1.0.6.110, R7960P before 1.4.1.66, R7900P before 1.4.1.66, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, and RAX200 before 1.0.3.106.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29072 β€Ό

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29074 β€Ό

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects RBW30 before 2.6.2.2, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29078 β€Ό

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
07:38
β€Ό CVE-2021-29075 β€Ό

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects RBW30 before 2.6.2.2, RBK852 before 3.2.17.12, RBK852 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.

πŸ“– Read

via "National Vulnerability Database".
?
11:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Phony COVID-19 vaccine certificates are now selling on the Dark Web 🦿

With most of the world still not vaccinated against COVID-19, criminals are hawking fake vaccine documents, says Check Point Research.

πŸ“– Read

via "Tech Republic".
11:40
❌ Energy Giant Shell Is Latest Victim of Accellion Attacks ❌

Attackers accessed personal and business data from the company’s legacy file-transfer service in a recent data-security incident but core IT systems remained untouched.

πŸ“– Read

via "Threat Post".
?
12:26
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Cartoon Caption Winner: In Hot Water πŸ•΄

And the winner of The Edge's March cartoon caption contest is ...

πŸ“– Read

via "Dark Reading".
?
12:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How remote working still poses security risks for organizations 🦿

A year after the transition to remote working, many organizations continue to grapple with security issues and weaknesses, says PC Matic.

πŸ“– Read

via "Tech Republic".
?
13:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-27529 β€Ό

A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-27531 β€Ό

A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "query" parameter.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-27527 β€Ό

A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-27309 β€Ό

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-27528 β€Ό

A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-27969 β€Ό

Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-27530 β€Ό

A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in /index.php.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-27310 β€Ό

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-27526 β€Ό

A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter.

πŸ“– Read

via "National Vulnerability Database".
?
14:05
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ›  Global Socket 1.4.27 πŸ› 

Global Socket is a tool for moving data from here to there, securely, fast, and through NAT and firewalls. It uses the Global Socket Relay Network to connect TCP pipes, has end-to-end encryption (using OpenSSL's SRP / RFC-5054), AES-256 and key exchange using 4096-bit Prime, requires no PKI, has Perfect Forward Secrecy, and TOR support.

πŸ“– Read

via "Packet Storm Security".
14:10
❌ Podcast: Microsoft Exchange Server Attack Onslaught Continues ❌

Derek Manky, Chief of Security Insights & Global Threat Alliances at Fortinet’s FortiGuard Labs, gives insight into the surge in attacks against vulnerable Microsoft Exchange servers over the last week.

πŸ“– Read

via "Threat Post".
?
14:26
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Disrupting the Cybercriminal Supply Chain πŸ•΄

It is time to turn the tables on cybercriminals and use their own tactics against them.

πŸ“– Read

via "Dark Reading".
?
15:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-23362 β€Ό

The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via shortcutMatch in fromUrl().

πŸ“– Read

via "National Vulnerability Database".
15:38
β€Ό CVE-2020-12483 β€Ό

The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.

πŸ“– Read

via "National Vulnerability Database".
15:38
β€Ό CVE-2020-7346 β€Ό

Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker's choosing. This requires the creation and removal of junctions by the attacker along with sending a specific IOTL command at the correct time.

πŸ“– Read

via "National Vulnerability Database".
15:38
β€Ό CVE-2021-21377 β€Ό

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.

πŸ“– Read

via "National Vulnerability Database".
15:38
β€Ό CVE-2021-21376 β€Ό

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0.

πŸ“– Read

via "National Vulnerability Database".
15:38
β€Ό CVE-2021-23274 β€Ό

The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO API Exchange Gateway: versions 2.3.3 and below and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric: versions 2.3.3 and below.

πŸ“– Read

via "National Vulnerability Database".
15:38
β€Ό CVE-2021-20222 β€Ό

A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

πŸ“– Read

via "National Vulnerability Database".
15:38
β€Ό CVE-2021-20227 β€Ό

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

πŸ“– Read

via "National Vulnerability Database".
15:38
β€Ό CVE-2021-20219 β€Ό

A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity check) and cause a threat to the system availability.

πŸ“– Read

via "National Vulnerability Database".
15:38
β€Ό CVE-2021-20270 β€Ό

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

πŸ“– Read

via "National Vulnerability Database".
?
15:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Why it's time the Android developers rethink WebView 🦿

Jack Wallen offers up his take on the recent issue surrounding Android's WebView.

πŸ“– Read

via "Tech Republic".
?
16:56
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Do Cybercriminals Fear Arrest? πŸ•΄

Researchers explore how cybercriminals weigh the possibility of arrest and whether it deters criminal activity.

πŸ“– Read

via "Dark Reading".
17:10
❌ Hobby Lobby Exposes Customer Data in Cloud Misconfiguration ❌

The arts-and-crafts retailer left 138GB of sensitive information open to the public internet.

πŸ“– Read

via "Threat Post".
17:10
❌ Office 365 Cyberattack Lands Disgruntled IT Contractor in Jail ❌

A former IT contractor is facing jailtime after a retaliatory hack into a company’s network and wiping the majority of its employees’ Microsoft Office 365 accounts.

πŸ“– Read

via "Threat Post".
17:10
❌ MangaDex Site Offline Following Hacking Incident ❌

A cyberattacker taunted the site about open security vulnerabilities, prompting a code review.

πŸ“– Read

via "Threat Post".
?
17:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Gartner: Top security and risk management trends for 2021 🦿

The 8 top trends cited will enable rapid reinvention, including the skills gap, cybersecurity mesh and identity-first security.

πŸ“– Read

via "Tech Republic".
17:38
β€Ό CVE-2021-21401 β€Ό

Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, decoding a specifically formed message can cause invalid `free()` or `realloc()` calls if the message type contains an `oneof` field, and the `oneof` directly contains both a pointer field and a non-pointer field. If the message data first contains the non-pointer field and then the pointer field, the data of the non-pointer field is incorrectly treated as if it was a pointer value. Such message data rarely occurs in normal messages, but it is a concern when untrusted data is parsed. This has been fixed in versions 0.3.9.8 and 0.4.5. See referenced GitHub Security Advisory for more information including workarounds.

πŸ“– Read

via "National Vulnerability Database".
17:38
β€Ό CVE-2021-3444 β€Ό

The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could potentially lead to code execution. This issue was addressed in the upstream kernel in commit 9b00f1b78809 ("bpf: Fix truncation handling for mod32 dst reg wrt zero") and in Linux stable kernels 5.11.2, 5.10.19, and 5.4.101.

πŸ“– Read

via "National Vulnerability Database".
17:41
❌ Security Analysis Clears TikTok of Censorship, Privacy Accusations   ❌

TikTok’s source code is in line with industry standards, security researchers say.

πŸ“– Read

via "Threat Post".
?
17:56
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Organizations Making Little Headway in Addressing Human Risk πŸ•΄

Most enterprise security awareness efforts remain half-hearted, a new SANS survey shows.

πŸ“– Read

via "Dark Reading".
?
18:26
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Disgruntled IT Contractor Sentenced in Retaliatory Office 365 Attack πŸ•΄

Former contractor deleted 1,200 user accounts in revenge.

πŸ“– Read

via "Dark Reading".
?
19:26
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Anti-Spoofing for Email Gains Adoption, but Enforcement Lags πŸ•΄

More organizations adopt sender authentication, but strict quarantining or rejection of unauthenticated messages remains uncommon.

πŸ“– Read

via "Dark Reading".
19:26
πŸ•΄ Inside the Web Shell Used in the Microsoft Exchange Server Attacks πŸ•΄

The history and details of China Chopper - a Web shell commonly seen in the widespread Microsoft Exchange Server attacks.

πŸ“– Read

via "Dark Reading".
19:29
🦿 REvil continues ransomware attack streak with takeover of laptop maker Acer 🦿

REvil previously infected the networks of Honda, the makers of Jack Daniels and a high-profile law firm representing Donald Trump.

πŸ“– Read

via "Tech Republic".
19:38
β€Ό CVE-2021-28100 β€Ό

Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2019-19343 β€Ό

A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-3409 β€Ό

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-21402 β€Ό

Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system. This issue is more prevalent when Windows is used as the host OS. Servers that are exposed to the public Internet are potentially at risk. This is fixed in version 10.7.1. As a workaround, users may be able to restrict some access by enforcing strict security permissions on their filesystem, however, it is recommended to update as soon as possible.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-27908 β€Ό

In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in MauticÒ€ℒs configuration that are used in publicly facing parts of the application.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-28823 β€Ό

The Windows Installation component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO eFTL - Community Edition: versions 6.5.0 and below, TIBCO eFTL - Developer Edition: versions 6.5.0 and below, and TIBCO eFTL - Enterprise Edition: versions 6.5.0 and below.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-28099 β€Ό

In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-28824 β€Ό

The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: versions 4.5.0 and below, TIBCO ActiveSpaces - Developer Edition: versions 4.5.0 and below, and TIBCO ActiveSpaces - Enterprise Edition: versions 4.5.0 and below.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-28819 β€Ό

The Windows Installation component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.5.0 and below, TIBCO FTL - Developer Edition: versions 6.5.0 and below, and TIBCO FTL - Enterprise Edition: versions 6.5.0 and below.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-28820 β€Ό

The FTL Server (tibftlserver), FTL C API, FTL Golang API, FTL Java API, and FTL .Net API components of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from the affected component searching for run-time artifacts outside of the installation hierarchy. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.5.0 and below, TIBCO FTL - Developer Edition: versions 6.5.0 and below, and TIBCO FTL - Enterprise Edition: versions 6.5.0 and below.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-28822 β€Ό

The Enterprise Message Service Server (tibemsd), Enterprise Message Service Central Administration (tibemsca), Enterprise Message Service JSON configuration generator (tibemsconf2json), and Enterprise Message Service C API components of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from the affected component searching for run-time artifacts outside of the installation hierarchy. Affected releases are TIBCO Software Inc.'s TIBCO Enterprise Message Service: versions 8.5.1 and below, TIBCO Enterprise Message Service - Community Edition: versions 8.5.1 and below, and TIBCO Enterprise Message Service - Developer Edition: versions 8.5.1 and below.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2020-24994 β€Ό

Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.14.0 allows remote attackers to cause a denial of service or remote code execution via a crafted file.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-28817 β€Ό

The Windows Installation component of TIBCO Software Inc.'s TIBCO Rendezvous and TIBCO Rendezvous Developer Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO Rendezvous: versions 8.5.1 and below and TIBCO Rendezvous Developer Edition: versions 8.5.1 and below.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-3392 β€Ό

A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-28818 β€Ό

The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), Rendezvous Secure C API, Rendezvous Java API, and Rendezvous .Net API components of TIBCO Software Inc.'s TIBCO Rendezvous and TIBCO Rendezvous Developer Edition contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from the affected component searching for run-time artifacts outside of the installation hierarchy. Affected releases are TIBCO Software Inc.'s TIBCO Rendezvous: versions 8.5.1 and below and TIBCO Rendezvous Developer Edition: versions 8.5.1 and below.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2021-28821 β€Ό

The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO Enterprise Message Service: versions 8.5.1 and below, TIBCO Enterprise Message Service - Community Edition: versions 8.5.1 and below, and TIBCO Enterprise Message Service - Developer Edition: versions 8.5.1 and below.

πŸ“– Read

via "National Vulnerability Database".
?
20:55
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ BlackKingdom ransomware still exploiting insecure Exchange servers ⚠

Remember Hafnium? Here's the bad news - it's not over yet! Learn why and what to do...

πŸ“– Read

via "Naked Security".
?
21:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-13606 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2020-13605 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2020-13607 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2020-13604 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2020-13611 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2020-13609 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2021-22864 β€Ό

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to override environment variables leading to code execution on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.0.3 and was fixed in 3.0.3, 2.22.9, and 2.21.17. This vulnerability was reported via the GitHub Bug Bounty program.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2020-13612 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2020-13608 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2020-13610 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2021-21380 β€Ό

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and only those with the Ratings API installed), the Rating Script Service expose an API to perform SQL requests without escaping the from and where search arguments. This might lead to an SQL script injection quite easily for any user having Script rights on XWiki. The problem has been patched in XWiki 12.9RC1. The only workaround besides upgrading XWiki would be to uninstall the Ratings API in XWiki from the Extension Manager.

πŸ“– Read

via "National Vulnerability Database".
11 June 2021
?
07:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-28814 β€Ό

An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4.

πŸ“– Read

via "National Vulnerability Database".
?
08:44
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Hackers Steal FIFA 21 Source Code, Tools in EA Breach ❌

Raft of other proprietary game data and related software and developer kits also pilfered in the unspecified attack, which the company is investigating.

πŸ“– Read

via "Threat Post".
?
09:44
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Police Grab Slilpp, Biggest Stolen-Logins Market ❌

There were more than 80 million login credentials for sale, used to inflict over $200 million in losses in the U.S. alone.

πŸ“– Read

via "Threat Post".
?
11:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Secure Access Trade-offs for DevSecOps Teams πŸ•΄

Thanks to recent advancements in access technologies, everyone can apply identity-based authentication and authorization and zero-trust principles for their computing resources.

πŸ“– Read

via "Dark Reading".
?
11:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-26829 β€Ό

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

πŸ“– Read

via "National Vulnerability Database".
11:44
❌ Monumental Supply-Chain Attack on Airlines Traced to State Actor ❌

Airlines are warned to scour networks for traces of the campaign, likely the work of APT41, lurking in networks.

πŸ“– Read

via "Threat Post".
?
12:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Many Mobile Apps Intentionally Using Insecure Connections for Sending Data πŸ•΄

A new analysis of iOS and Android apps released to Apple's and Google's app stores over the past five years found many to be deliberately breaking HTTPS protections.

πŸ“– Read

via "Dark Reading".
?
12:42
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ” Friday Five 6/11 πŸ”

TrickBot indictments, ransomware negotiations, and a massive sting operation using an FBI-run phone network - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "".
12:45
πŸ›  GNU Privacy Guard 2.2.28 πŸ› 

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions. This is the LTS release.

πŸ“– Read

via "Packet Storm Security".
12:45
πŸ›  nfstream 6.3.2 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Read

via "Packet Storm Security".
?
13:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-25401 β€Ό

Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.

πŸ“– Read

via "National Vulnerability Database".
13:36
β€Ό CVE-2021-25385 β€Ό

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2021-25397 β€Ό

An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.

πŸ“– Read

via "National Vulnerability Database".
13:39
⚠ Chrome zero-day, hot on the heels of Microsoft’s IE zero-day. Patch now! ⚠

Patch early. Patch often. Patch now!

πŸ“– Read

via "Naked Security".
13:39
⚠ ALPACA – the wacky TLS security vulnerability with a funky name ⚠

Don't panic - this isn't another Heartbleed. But it's a fascinating reminder of why doing things the easy way isn't always the best way.

πŸ“– Read

via "Naked Security".
13:39
⚠ S3 Ep36: Trickbot coder busted, passwords cracked, and breaches judged [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
13:42
β€Ό CVE-2021-25419 β€Ό

Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link.

πŸ“– Read

via "National Vulnerability Database".
13:42
β€Ό CVE-2021-29754 β€Ό

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.

πŸ“– Read

via "National Vulnerability Database".
13:43
β€Ό CVE-2020-5003 β€Ό

IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.

πŸ“– Read

via "National Vulnerability Database".
13:43
β€Ό CVE-2021-25425 β€Ό

Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component.

πŸ“– Read

via "National Vulnerability Database".
13:45
❌ Cyberpunk 2077 Hacked Data Circulating Online ❌

CD Projekt Red confirmed that employee and game-related data appears to be floating around the cyber-underground, four months after a hack on the Witcher and Cyberpunk 2077 developer.

πŸ“– Read

via "Threat Post".
13:51
πŸ•΄ Details Emerge on How Gaming Giant EA Was Hacked πŸ•΄

Hacking group stole source code to FIFA 21 and the company's Frostbite engine.

πŸ“– Read

via "Dark Reading".
?
15:21
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Fallout of EA source code breach could be severe, cybersecurity experts say 🦿

Potential buyers could be interested in using the source code to game the game to make millions, perhaps sounding EA's death knell in the process.

πŸ“– Read

via "Tech Republic".
?
15:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-6000 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
15:37
β€Ό CVE-2021-23136 β€Ό

Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); version 8.10 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
15:43
β€Ό CVE-2021-22913 β€Ό

Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only the local Nextcloud server unless a global search has been explicitly chosen by the user.

πŸ“– Read

via "National Vulnerability Database".
15:43
β€Ό CVE-2021-28211 β€Ό

A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.

πŸ“– Read

via "National Vulnerability Database".
15:43
β€Ό CVE-2017-3905 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
15:46
❌ REvil Hits US Nuclear Weapons Contractor: Report ❌

"We hereby keep a right (sic) to forward all of the relevant documentation and data to military agencies of our choise (sic)" REvil reportedly wrote.

πŸ“– Read

via "Threat Post".
15:46
❌ Baby Clothes Giant Carter’s Leaks 410K Customer Records ❌

Purchase automation software delivered shortened URLs without protections.

πŸ“– Read

via "Threat Post".
15:49
β€Ό CVE-2021-22753 β€Ό

A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition.

πŸ“– Read

via "National Vulnerability Database".
15:52
β€Ό CVE-2021-22915 β€Ό

Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.

πŸ“– Read

via "National Vulnerability Database".
15:52
β€Ό CVE-2021-0491 β€Ό

In memory management driver, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-183461315

πŸ“– Read

via "National Vulnerability Database".
15:52
β€Ό CVE-2021-23204 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to Command Centre Operators. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3).

πŸ“– Read

via "National Vulnerability Database".
?
17:21
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ McDonald's Data Breach Exposed Business & Customer Data πŸ•΄

An investigation has revealed company data has been breached in the United States, South Korea, and Taiwan.

πŸ“– Read

via "Dark Reading".
?
17:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-27200 β€Ό

In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.

πŸ“– Read

via "National Vulnerability Database".
17:51
πŸ•΄ Trickbot Investigation Shows Details of Massive Cybercrime Effort πŸ•΄

Nearly a score of cybercriminals allegedly worked together to create the Trickbot malware and deploy it against more than a million users, an unsealed indictment claims.

πŸ“– Read

via "Dark Reading".
?
18:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Unpatched Bugs Found Lurking in Provisioning Platform Used with Cisco UC ❌

A trio of security flaws open the door to remote-code execution and a malware tsunami.

πŸ“– Read

via "Threat Post".
18:18
🦿 McDonald's suffers cyberattack in US, South Korea and Taiwan 🦿

The restaurant chain reportedly said no U.S. customer data was exposed and the attack did not involve ransomware.

πŸ“– Read

via "Tech Republic".
?
19:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2017-5730 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2017-5755 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2017-3918 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2017-3913 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
19:43
β€Ό CVE-2017-3919 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
19:43
β€Ό CVE-2017-5690 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
19:43
β€Ό CVE-2021-34679 β€Ό

Thycotic Password Reset Server before 5.3.0 allows credential disclosure.

πŸ“– Read

via "National Vulnerability Database".
19:43
β€Ό CVE-2017-5765 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
?
21:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-12909 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:37
β€Ό CVE-2020-12999 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:37
β€Ό CVE-2020-13007 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:43
β€Ό CVE-2020-12975 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:43
β€Ό CVE-2020-12923 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:43
β€Ό CVE-2020-12997 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:48
β€Ό CVE-2020-12971 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:48
β€Ό CVE-2008-2660 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2008. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
12 June 2021
?
02:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32552 β€Ό

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.

πŸ“– Read

via "National Vulnerability Database".
02:37
β€Ό CVE-2021-32551 β€Ό

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could expose private data to other local users.

πŸ“– Read

via "National Vulnerability Database".
?
09:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-31811 β€Ό

In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

πŸ“– Read

via "National Vulnerability Database".
?
19:45
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-34682 β€Ό

Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.

πŸ“– Read

via "National Vulnerability Database".
13 June 2021
?
09:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-23394 β€Ό

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

πŸ“– Read

via "National Vulnerability Database".
14 June 2021
?
07:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-21439 β€Ό

DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions; 8.0.x version 8.0.13 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
?
10:23
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Colonial Pipeline Cyberattack Proves a Single Password Isn't Enough πŸ•΄

Since the attack, it's been revealed that it was down to a single password. Yes, ransomware needs to be on your radar -- but a focus on credentials is vital.

πŸ“– Read

via "Dark Reading".
?
10:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Name That Toon: Sight Unseen πŸ•΄

Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
?
11:23
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Know Thy Enemy: Fighting Half-Blind Against Ransomware Won't Work πŸ•΄

We lack reliable, representative, actionable data about ransomware's actual scope, scale, and impact. The Ransom Incident Response Network could change that.

πŸ“– Read

via "Dark Reading".
?
12:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Volkswagen Vendor Exposed Data of 3.3m Drivers ❌

Nearly all of the leaked data was for owners or wannabe owners of the automaker’s luxury brand of Audis, now at greater risk for phishing, ransomware or car theft.

πŸ“– Read

via "Threat Post".
?
13:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-24350 β€Ό

The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display the user's user agent string without validation or encoding within the WordPress admin panel.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2021-24349 β€Ό

This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the attack could also be performed via such vector.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2021-24355 β€Ό

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.

πŸ“– Read

via "National Vulnerability Database".
?
14:47
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Moobot Milks Tenda Router Bugs for Propagation ❌

An analysis of the campaign revealed Cyberium, an active Mirai-variant malware hosting site.

πŸ“– Read

via "Threat Post".
?
15:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Why employees need counterespionage training 🦿

Two experts are concerned that employees are no match for nation-state spy services tasked with obtaining a company's vital intellectual property.

πŸ“– Read

via "Tech Republic".
?
15:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32682 β€Ό

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.

πŸ“– Read

via "National Vulnerability Database".
?
15:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ New Top 20 Secure-Coding List Positions PLCs as Plant 'Bodyguards' πŸ•΄

Best practices guide encompasses integrity, hardening, resilience, and monitoring of PLCs in industrial networks.

πŸ“– Read

via "Dark Reading".
?
17:14
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ” Colorado Passes State Privacy Act, Poised to Become Law πŸ”

Once it's signed into law, the bill will become the third comprehensive state privacy law in the U.S. after California and Virginia.

πŸ“– Read

via "".
17:23
πŸ•΄ Google Workspace Adds Client-Side Encryption πŸ•΄

Users given control over encryption keys, Google says.

πŸ“– Read

via "Dark Reading".
17:37
β€Ό CVE-2021-21556 β€Ό

Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a stack-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.

πŸ“– Read

via "National Vulnerability Database".
17:46
❌ Utilities β€˜Concerningly’ at Risk from Active Exploits ❌

Utilities’ vulnerability to application exploits goes from bad to worse in just weeks. Β 

πŸ“– Read

via "Threat Post".
?
18:23
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Cyber Analytics Database Exposed 5 Billion Records Online πŸ•΄

In an ironic twist, Cognyte's data alerts customers to third-party data exposures.

πŸ“– Read

via "Dark Reading".
?
19:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-0324 β€Ό

Product: AndroidVersions: Android SoCAndroid ID: A-175402462

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-0467 β€Ό

In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the bootloader, with physical USB access, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-174490700

πŸ“– Read

via "National Vulnerability Database".
?
20:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ VPN Attacks Surged in First Quarter πŸ•΄

But volume of malware, botnet, and other exploit activity declined because of the Emotet botnet takedown.

πŸ“– Read

via "Dark Reading".
?
21:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-34693 β€Ό

net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2021-27887 β€Ό

Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victimÒ€ℒs browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and prior versions; 5.2 version 5.2.0.3 and prior versions; 5.1 version 5.1.0.6 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
15 June 2021
?
07:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-31618 β€Ό

Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such a triggering HTTP/2 request is easy to craft and submit, this can be exploited to DoS the server. This issue affected mod_http2 1.15.17 and Apache HTTP Server version 2.4.47 only. Apache HTTP Server 2.4.47 was never released.

πŸ“– Read

via "National Vulnerability Database".
?
08:47
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Apple Hurries Patches for Safari Bugs Under Active Attack ❌

Apple patched two bugs impacting its Safari browser WebKit engine that it said are actively being exploited.

πŸ“– Read

via "Threat Post".
?
09:40
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ β€œFace of Anonymous” suspect deported from Mexico to face US hacking charges ⚠

After nearly a decade as a US expat dubbed "The Face of Anoynmous", he's back in the US facing cybercrime charges from almost a decade ago.

πŸ“– Read

via "Naked Security".
09:47
❌ Microsoft Gets Second Shot at Banning hiQ from Scraping LinkedIn User Data ❌

Decision throws out previous ruling in favor of hiQ Labs that prevented Microsoft’s business networking platform to forbid the company from harvesting public info from user profiles.

πŸ“– Read

via "Threat Post".
?
10:48
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Microsoft product vulnerabilities reached a new high of 1,268 in 2020 🦿

56% of all Microsoft critical vulnerabilities could have been mitigated by removing admin rights, according to the 2021 BeyondTrust Microsoft Vulnerabilities Report.

πŸ“– Read

via "Tech Republic".
?
11:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ How Does the Government Buy Its Cybersecurity? πŸ•΄

The federal government is emphasizing cybersecurity regulation, education, and defense strategies this year.

πŸ“– Read

via "Dark Reading".
?
12:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ SASE & Zero Trust: The Dream Team ❌

Forcepoint’s Nico Fischbach, global CTO and VPE of SASE, and Chase Cunningham, chief strategy officer at Ericom Software, on using SASE to make Zero Trust real.

πŸ“– Read

via "Threat Post".
?
12:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ›  Hashcat Advanced Password Recovery 6.2.2 Source Code πŸ› 

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
?
13:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ How President Biden Can Better Defend the US From Russian Hacks πŸ•΄

Wilson Center cybersecurity expert Meg King pinpoints five ambitious steps the administration should take, including a comprehensive national data breach notification protocol.

πŸ“– Read

via "Dark Reading".
?
14:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Microsoft Disrupts Large-Scale, Cloud-Based BEC Campaign ❌

Varied cloud infrastructure was used to phish email credentials, monitor for and forward finance-related messages and automate operations.

πŸ“– Read

via "Threat Post".
14:17
❌ Malicious PDFs Flood the Web, Lead to Password-Snarfing ❌

SolarMarker makers are using SEO poisoning, stuffing thousands of PDFs with tens of thousands of pages full of SEO keywords & links to redirect to the malware.

πŸ“– Read

via "Threat Post".
14:29
πŸ•΄ What Industrial Control System Vulnerabilities Can Teach Us About Protecting the Supply Chain πŸ•΄

Older technologies used in industrial and critical infrastructure leave the sector highly vulnerable to attack, but organizations can take steps to better protect themselves.

πŸ“– Read

via "Dark Reading".
?
15:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Deloitte Buys Terbium Labs to Expand Threat Intel Capabilities πŸ•΄

Terbium Labs' products and services will become part of Deloitte's Detect & Respond lineup, the company confirms.

πŸ“– Read

via "Dark Reading".
?
17:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-31497 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of DWG files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13311.

πŸ“– Read

via "National Vulnerability Database".
17:39
β€Ό CVE-2021-31487 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12715.

πŸ“– Read

via "National Vulnerability Database".
?
17:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Andariel Group Targets South Korean Entities in New Campaign πŸ•΄

Andariel, designated as a sub-group of the Lazarus Group APT, has historically targeted South Korean organzations.

πŸ“– Read

via "Dark Reading".
?
18:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Millions of Connected Cameras Open to Eavesdropping ❌

A supply-chain component lays open camera feeds to remote attackers thanks to a critical security vulnerability.

πŸ“– Read

via "Threat Post".
18:29
πŸ•΄ Security Experts Scrutinize Apple, Amazon IoT Networks πŸ•΄

Both companies have done their due diligence in creating connected-device networks, but the pervasiveness of the devices worries some security researchers.

πŸ“– Read

via "Dark Reading".
?
18:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Microsoft Disrupts Large-Scale BEC Campaign Across Web Services πŸ•΄

Attackers had used the cloud-based infrastructure to target mailboxes and add forwarding rules to learn about financial transactions.

πŸ“– Read

via "Dark Reading".
?
19:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Thousands of VMware vCenter Servers Remain Open to Attack Over the Internet πŸ•΄

Three weeks after company disclosed two critical vulnerabilities in the workload management utility, many organizations have not patched the technology yet, security vendor says.

πŸ“– Read

via "Dark Reading".
19:39
β€Ό CVE-2021-34170 β€Ό

Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
19:39
β€Ό CVE-2020-21316 β€Ό

A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.

πŸ“– Read

via "National Vulnerability Database".
?
21:39
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-30550 β€Ό

Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
21:39
β€Ό CVE-2021-24037 β€Ό

A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

πŸ“– Read

via "National Vulnerability Database".
16 June 2021
?
02:39
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32623 β€Ό

Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to 9.6 are vulnerable to the billion laughs attack, which allows an attacker to easily execute a (seemingly permanent) denial of service attack, essentially taking down Opencast using a single HTTP request. To exploit this, users need to have ingest privileges, limiting the group of potential attackers The problem has been fixed in Opencast 9.6. There is no known workaround for this issue.

πŸ“– Read

via "National Vulnerability Database".
?
07:39
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-9493 β€Ό

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

πŸ“– Read

via "National Vulnerability Database".
?
08:48
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Peloton Bike+ Bug Gives Hackers Complete Control ❌

An attacker with initial physical access (say, at a gym) could gain root entry to the interactive tablet, making for a bevy of remote attack scenarios.

πŸ“– Read

via "Threat Post".
?
09:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Researchers: Booming Cyber-Underground Market for Initial-Access Brokers ❌

Ransomware gangs are increasingly buying their way into corporate networks, purchasing access from 'vendors' that have previously installed backdoors on targets.

πŸ“– Read

via "Threat Post".
?
09:39
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-21441 β€Ό

There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending specially crafted e-mail to the system and it doesn't require any user intraction. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
?
10:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ 5 Tips to Prevent and Mitigate Ransomware Attacks ❌

Ransomware attacks are increasing in frequency, and the repercussions are growing more severe than ever. Here are 5 ways to prevent your company from becoming the next headline.

πŸ“– Read

via "Threat Post".
?
10:48
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 The many ways a ransomware attack can hurt your organization 🦿

Loss of revenue, brand and reputation damage, employee layoffs and business closures were some of the effects of a ransomware attack, according to Cybereason.

πŸ“– Read

via "Tech Republic".
?
11:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ Clop ransomware suspects busted in Ukraine, money and motors seized ⚠

Victims in South Korea and the USA, suspects busted in Ukraine.

πŸ“– Read

via "Naked Security".
?
11:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Don't Get Stymied by Security Indecision πŸ•΄

You might be increasing cyber-risk by not actively working to reduce it.

πŸ“– Read

via "Dark Reading".
11:39
β€Ό CVE-2021-27485 β€Ό

ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.

πŸ“– Read

via "National Vulnerability Database".
11:39
β€Ό CVE-2021-31857 β€Ό

In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.

πŸ“– Read

via "National Vulnerability Database".
?
12:19
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Akamai adds automation and machine learning to protect user accounts, APIs and applications 🦿

Edge platform cybersecurity enhancements are intended to increase responsiveness and augment decision-making, the company said.

πŸ“– Read

via "Tech Republic".
?
13:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Euros-Driven Football Fever Nets Dumb Passwords ❌

The top easy-to-crack, football-inspired password in a database of 1 billion unique, clear-text, breached passwords? You probably guessed it: "Football."

πŸ“– Read

via "Threat Post".
?
13:40
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-21668 β€Ό

Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.

πŸ“– Read

via "National Vulnerability Database".
13:40
β€Ό CVE-2020-8299 β€Ό

Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment. Note that the attacker must be in the same Layer 2 network segment as the vulnerable appliance.

πŸ“– Read

via "National Vulnerability Database".
13:48
❌ Takeaways from the Colonial Pipeline Ransomware Attack ❌

The incident showcases basic steps that organizations can take to protect themselves as ransomware gangs get smarter.

πŸ“– Read

via "Threat Post".
?
14:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Keeping Your Organization Secure When Dealing With the Unexpected πŸ•΄

There's no way to anticipate every possible scenario, but the right approach to business continuity can help you respond effectively in any situation.

πŸ“– Read

via "Dark Reading".
?
15:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Ransomware Poll: 80% of Victims Don’t Pay Up ❌

Meanwhile, in a separate survey, 80 percent of organizations that paid the ransom said were hit by a second attack.

πŸ“– Read

via "Threat Post".
15:30
πŸ•΄ Is an Attacker Living Off Your Land? πŸ•΄

Living-off-the-land attacks pose significant risks to organizations and, on top of that, are difficult to detect. Learn the basics about how these attacks operate and ways to limit their damage.

πŸ“– Read

via "Dark Reading".
15:40
β€Ό CVE-2020-20444 β€Ό

Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .

πŸ“– Read

via "National Vulnerability Database".
15:40
β€Ό CVE-2020-22199 β€Ό

SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.

πŸ“– Read

via "National Vulnerability Database".
15:48
❌ IKEA Fined $1.2M for Elaborate β€˜Spying System’ ❌

A French court fined the furniture giant for illegal surveillance on 400 customers and staff.

πŸ“– Read

via "Threat Post".
?
16:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Russian National Convicted on Charges Related to Kelihos Botnet πŸ•΄

Oleg Koshkin was arrested in 2019 and faces a maximum penalty of 15 years in prison, the DoJ reports.

πŸ“– Read

via "Dark Reading".
?
17:00
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Security Flaw Discovered In Peloton Equipment πŸ•΄

The vulnerability could give attackers remote root access to the bike's tablet, researchers report.

πŸ“– Read

via "Dark Reading".
17:00
πŸ•΄ Biden Tells Putin Critical Infrastructure Sectors 'Off Limits' to Russian Hacking πŸ•΄

President Joe Biden said he and Russian President Vladimir Putin agreed to discuss boundaries in cyber activity.

πŸ“– Read

via "Dark Reading".
?
17:40
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-1568 β€Ό

A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to uncontrolled memory allocation. An attacker could exploit this vulnerability by copying a crafted file to a specific folder on the system. A successful exploit could allow the attacker to crash the VPN Agent service when the affected application is launched, causing it to be unavailable to all users of the system. To exploit this vulnerability, the attacker must have valid credentials on a multiuser Windows system.

πŸ“– Read

via "National Vulnerability Database".
17:40
β€Ό CVE-2021-1541 β€Ό

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
?
18:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Ransomware Operators' Strategies Evolve as Attacks Rise πŸ•΄

Security researchers find ransomware operators rely less on email and more on criminal groups for initial access into target networks.

πŸ“– Read

via "Dark Reading".
?
19:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Ukraine Police Disrupt Cl0p Ransomware Operation πŸ•΄

Growing list of similar actions in recent months may finally be scaring some operators into quitting, but threat is far from over, security experts say.

πŸ“– Read

via "Dark Reading".
19:40
β€Ό CVE-2021-34201 β€Ό

D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, causing the process crashes or changes.

πŸ“– Read

via "National Vulnerability Database".
19:40
β€Ό CVE-2021-34204 β€Ό

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same, and they cannot be modified by normal users. An attacker can easily log in to the target router through the serial port and obtain root privileges.

πŸ“– Read

via "National Vulnerability Database".
19:40
β€Ό CVE-2021-32243 β€Ό

FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).

πŸ“– Read

via "National Vulnerability Database".
?
21:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ How to hack a bicycle – Peloton Bike+ rooting bug patched ⚠

It's a bike, Jim, but not as we know it.

πŸ“– Read

via "Naked Security".
?
21:40
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-31476 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA templates. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13531.

πŸ“– Read

via "National Vulnerability Database".
17 June 2021
?
09:40
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-21777 β€Ό

An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead to an out-of-bounds read.

πŸ“– Read

via "National Vulnerability Database".
?
10:19
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Threat Actors Use Google Docs to Host Phishing Attacks ❌

Exploit in the widely used document service leveraged to send malicious links that appear legitimate but actually steal victims credentials.

πŸ“– Read

via "Threat Post".
?
11:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ S3 Ep37: Quantum crypto, refunding Bitcoins, and Alpaca problems [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
11:19
🦿 Amazon Prime Day scams resurface for 2021 🦿

With this year's Amazon Prime Day set for June 21-22, scammers are already touting "Early Prime Day Deals," says Bolster.

πŸ“– Read

via "Tech Republic".
11:30
πŸ•΄ Mission Critical: What Really Matters in a Cybersecurity Incident πŸ•΄

The things you do before and during a cybersecurity incident can make or break the success of your response.

πŸ“– Read

via "Dark Reading".
11:40
β€Ό CVE-2021-32946 β€Ό

An improper check for unusual or exceptional conditions issue exists within the parsing DGN files from Drawings SDK (Version 2022.4 and prior) resulting from the lack of proper validation of the user-supplied data. This may result in several of out-of-bounds problems and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
11:41
β€Ό CVE-2021-32938 β€Ό

Drawings SDK (All versions prior to 2022.4) are vulnerable to an out-of-bounds read due to parsing of DWG files resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allows attackers to cause a denial-of service condition or read sensitive information from memory.

πŸ“– Read

via "National Vulnerability Database".
11:41
β€Ό CVE-2021-32950 β€Ό

An out-of-bounds read issue exists within the parsing of DXF files in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allows attackers to cause a denial-of-service condition or read sensitive information from memory locations.

πŸ“– Read

via "National Vulnerability Database".
11:41
β€Ό CVE-2021-32944 β€Ό

A use-after-free issue exists in the DGN file-reading procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a memory corruption or arbitrary code execution, allowing attackers to cause a denial-of-service condition or execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
11:41
β€Ό CVE-2021-32952 β€Ό

An out-of-bounds write issue exists in the DGN file-reading procedure in the Drawings SDK (Version 2022.4 and prior) resulting from the lack of proper validation of user-supplied data. This can result in a write past the end of an allocated buffer and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
11:41
β€Ό CVE-2021-32936 β€Ό

An out-of-bounds write issue exists in the DXF file-recovering procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a write past the end of an allocated buffer and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
?
13:41
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-34825 β€Ό

Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.

πŸ“– Read

via "National Vulnerability Database".
13:41
β€Ό CVE-2021-31818 β€Ό

Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isnÒ€ℒt parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.

πŸ“– Read

via "National Vulnerability Database".
13:49
❌ CVS Health Records for 1.1 Billion Customers Exposed ❌

A vendor exposed the records, which were accessible with no password or other authentication, likely because of a cloud-storage misconfiguration.

πŸ“– Read

via "Threat Post".
?
14:19
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Geek Squad Vishing Attack Bypasses Email Security to Hit 25K Mailboxes ❌

An email campaign asking victims to call a bogus number to suspend supposedly fraudulent subscriptions got right past Microsoft's native email controls.

πŸ“– Read

via "Threat Post".
14:31
πŸ•΄ Cyberattacks Are Tailored to Employees ... Why Isn't Security Training? πŸ•΄

Consider four factors and behaviors that impact a particular employee's risk, and how security training should take them into account.

πŸ“– Read

via "Dark Reading".
?
15:41
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-23396 β€Ό

All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.

πŸ“– Read

via "National Vulnerability Database".
15:41
β€Ό CVE-2013-20002 β€Ό

Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.

πŸ“– Read

via "National Vulnerability Database".
15:46
πŸ” What is Data Classification? A Data Classification Definition πŸ”

Learn about the different types of classification and how to effectively classify your data in Data Protection 101, our series on the fundamentals of data security.

πŸ“– Read

via "".
?
16:49
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Cisco Smart Switches Riddled with Severe Security Holes ❌

The intro-level networking gear for SMBs could allow remote attacks designed to steal information, drop malware and disrupt operations.

πŸ“– Read

via "Threat Post".
?
17:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32575 β€Ό

HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.

πŸ“– Read

via "National Vulnerability Database".
17:11
β€Ό CVE-2021-33557 β€Ό

An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.

πŸ“– Read

via "National Vulnerability Database".
?
17:49
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Clop Raid: A Big Win in the War on Ransomware? ❌

Cops arrest six, seize cars and cash in splashy raid, and experts are applauding.

πŸ“– Read

via "Threat Post".
18:01
πŸ•΄ Google Launches SLSA, A New Framework for Supply Chain Integrity πŸ•΄

The 'Supply chain Levels for Software Artifacts' aims to ensure the integrity of components throughout the software supply chain.

πŸ“– Read

via "Dark Reading".
?
18:31
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Carnival Cruise Line Reports Security Breach πŸ•΄

The cruise ship operator says the incident affected employee and guest data.

πŸ“– Read

via "Dark Reading".
?
19:31
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ One in Five Manufacturing Firms Targeted by Cyberattacks πŸ•΄

Information-stealing malware makes up about a third of attacks, a study finds, but companies worry most about ransomware shutting down production.

πŸ“– Read

via "Dark Reading".
19:41
β€Ό CVE-2021-32695 β€Ό

Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.16.1, a malicious app on the same device could have gotten access to the shared preferences of the Nextcloud Android application. This required user-interaction as a victim had to initiate the sharing flow and choose the malicious app. The shared preferences contain some limited private data such as push tokens and the account name. The vulnerability is patched in version 3.16.1.

πŸ“– Read

via "National Vulnerability Database".
?
20:06
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Data Breaches Surge in Food & Beverage, Other Industries πŸ•΄

Six previously "under-attacked" vertical industries saw a surge in data breaches last year due to COVID-19 related disruptions and other factors, new data shows.

πŸ“– Read

via "Dark Reading".
?
21:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32426 β€Ό

In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command.

πŸ“– Read

via "National Vulnerability Database".
21:11
β€Ό CVE-2021-32694 β€Ό

Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the same device is possible to crash the Nextcloud Android Client due to an uncaught exception. The vulnerability is patched in version 3.15.1.

πŸ“– Read

via "National Vulnerability Database".
18 June 2021
?
02:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-34811 β€Ό

Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
02:11
β€Ό CVE-2021-34553 β€Ό

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

πŸ“– Read

via "National Vulnerability Database".
?
08:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ” Friday Five 6/18 πŸ”

New data privacy acts, the G7 on ransomware, and how cybersecurity factors into M&As - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "".
08:19
🦿 Microsoft's new security tool will discover firmware vulnerabilities, and more, in PCs and IoT devices 🦿

Devices have multiple OSs and firmware running, and most organisations don't know what they have or if it's secure. Microsoft will use ReFirm to make it easier to find out without being an expert.

πŸ“– Read

via "Tech Republic".
?
09:20
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Faux β€˜DarkSide’ Gang Takes Aim at Global Energy, Food Sectors ❌

A DarkSide doppelganger mounts a fraud campaign aimed at extorting nearly $4 million from each target.

πŸ“– Read

via "Threat Post".
?
09:41
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-33576 β€Ό

An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.

πŸ“– Read

via "National Vulnerability Database".
09:41
β€Ό CVE-2021-32536 β€Ό

The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks.

πŸ“– Read

via "National Vulnerability Database".
09:50
❌ β€˜Oddball’ Malware Blocks Access to Pirated Software ❌

Rather than steal credentials or hold data for ransom, a recent campaign observed by Sophos prevents people from visiting sites that offer illegal downloads.

πŸ“– Read

via "Threat Post".
?
10:50
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Insider Versus Outsider: Navigating Top Data Loss Threats ❌

TroyΒ Gill, manager of security research at Zix, discusses the most common ways sensitive data is scooped up by nefarious sorts.

πŸ“– Read

via "Threat Post".
?
11:42
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2005-0394 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
11:42
β€Ό CVE-2021-26834 β€Ό

A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code execution will happen immediately on markdown view mode.

πŸ“– Read

via "National Vulnerability Database".
11:45
πŸ•΄ 4 Habits of Highly Effective Security Operators πŸ•΄



πŸ“– Read

via "Dark Reading".
?
12:20
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Carnival Cruise Cyber-Torpedoed by Cyberattack ❌

This is the fourth time in a bit over a year that Carnival’s admitted to breaches, with two of them being ransomware attacks.

πŸ“– Read

via "Threat Post".
?
12:50
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ What’s Making Your Company a Ransomware Sitting Duck ❌

What's the low-hanging fruit for ransomware attackers? What steps could help to fend them off, and what’s stopping organizations from implementing those steps?

πŸ“– Read

via "Threat Post".
?
13:12
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-3604 β€Ό

Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection. An attacker could exploit this vulnerability in order to extract information of users and administrator accounts stored in the database.

πŸ“– Read

via "National Vulnerability Database".
13:12
β€Ό CVE-2020-18442 β€Ό

Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".

πŸ“– Read

via "National Vulnerability Database".
?
14:01
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ 11 Security Certifications to Seek Out This Summer πŸ•΄

The more you know, the more you grow. The Edge takes a fresh look at leading security certifications that can help advance your security career.

πŸ“– Read

via "Dark Reading".
14:12
⚠ Can *YOU* blow a PC speaker using only a Linux kernel driver? ⚠

Can you help? There's a hidden meaning here, and it's time to find it!

πŸ“– Read

via "Naked Security".
14:12
⚠ S3 Ep37: Quantum crypto, refunding Bitcoins, and Alpaca problems [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
?
17:42
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-33818 β€Ό

An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

πŸ“– Read

via "National Vulnerability Database".
?
18:01
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Accidental Insider Leaks Prove Major Source of Risk πŸ•΄

Research reports highlight growing concerns around insider negligence that leads to data breaches.

πŸ“– Read

via "Dark Reading".
?
18:31
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Attackers Find New Way to Exploit Google Docs for Phishing πŸ•΄

Tactic continues recent trend by attackers to use trusted cloud services to send and host malicious content.

πŸ“– Read

via "Dark Reading".
?
19:42
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-33823 β€Ό

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.

πŸ“– Read

via "National Vulnerability Database".
19:42
β€Ό CVE-2021-33824 β€Ό

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

πŸ“– Read

via "National Vulnerability Database".
?
21:12
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-31272 β€Ό

SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
21:12
β€Ό CVE-2021-31662 β€Ό

RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
21:12
β€Ό CVE-2021-33186 β€Ό

SerenityOS in test-crypto.cpp contains a stack buffer overflow which could allow attackers to obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
20 June 2021
?
11:14
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-24368 β€Ό

The Quiz And Survey Master ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link

πŸ“– Read

via "National Vulnerability Database".
21 June 2021
?
02:14
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-20467 β€Ό

White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attackers can exploit the vulnerability to create a task.

πŸ“– Read

via "National Vulnerability Database".
02:14
β€Ό CVE-2020-20466 β€Ό

White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user.

πŸ“– Read

via "National Vulnerability Database".
?
07:14
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-20471 β€Ό

White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to escalate to admin privileges.

πŸ“– Read

via "National Vulnerability Database".
07:14
β€Ό CVE-2020-20473 β€Ό

White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.

πŸ“– Read

via "National Vulnerability Database".
?
09:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-31769 β€Ό

MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGRAMFILES%\MyQ\PHP\Sessions directory. The "Select server file" feature is only intended for administrators but actually does not require authorization. An attacker can inject arbitrary OS commands (such as commands to create new .php files) via the Task Scheduler component.

πŸ“– Read

via "National Vulnerability Database".
?
11:04
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Are Ransomware Attacks the New Pandemic? πŸ•΄

Ransomware has been a problem for decades, so why is government just now beginning to address it?

πŸ“– Read

via "Dark Reading".
11:15
β€Ό CVE-2020-7031 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
?
13:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-22390 β€Ό

Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.

πŸ“– Read

via "National Vulnerability Database".
13:15
β€Ό CVE-2006-0016 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
?
14:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ iPhone Wi-Fi Crushed by Weird Network ❌

… until you reset network settings and stop connecting to a weirdly named network, that is. FUD is spreading. iOS Wi-Fi demolition is not.

πŸ“– Read

via "Threat Post".
?
15:04
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Fintech at SaaS Speed πŸ•΄



πŸ“– Read

via "Dark Reading".
15:15
β€Ό CVE-2021-0522 β€Ό

In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-174182139

πŸ“– Read

via "National Vulnerability Database".
15:15
β€Ό CVE-2021-0520 β€Ό

In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-176237595

πŸ“– Read

via "National Vulnerability Database".
?
17:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-19510 β€Ό

Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

πŸ“– Read

via "National Vulnerability Database".
17:15
β€Ό CVE-2021-32697 β€Ό

neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted without invoking any validators. Form state is secured with an HMAC that is still verified. That means that this issue can only be exploited if Form Finishers cause side effects even if no form values have been sent. Form Finishers can be adjusted in a way that they only execute an action if the submitted form contains some expected data. Alternatively a custom Finisher can be added as first finisher. This regression was introduced with https://github.com/neos/form/commit/049d415295be8d4a0478ccba97dba1bb81649567

πŸ“– Read

via "National Vulnerability Database".
17:22
❌ Embryology Data Breach Follows Fertility Clinic Ransomware Hit ❌

Approximately 38,000 of RBA's customers had their embryology data stolen by a ransomware gang.

πŸ“– Read

via "Threat Post".
17:34
πŸ•΄ Baltimore County Public Schools' Ransomware Recovery Tops $8M πŸ•΄

The school district has spent seven months and a reported $8.1 million recovering from the November attack.

πŸ“– Read

via "Dark Reading".
?
17:52
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft ❌

Chipmaker patches nine high-severity bugs in its Jetson SoC framework tied to the way it handles low-level cryptographic algorithms.

πŸ“– Read

via "Threat Post".
?
19:04
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Data Leaked in Fertility Clinic Ransomware Attack πŸ•΄

Reproductive Biology Associates says the data of 38,000 patients may have been compromised in the April cyberattack.

πŸ“– Read

via "Dark Reading".
19:15
β€Ό CVE-2021-24377 β€Ό

The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.

πŸ“– Read

via "National Vulnerability Database".
19:15
β€Ό CVE-2021-24372 β€Ό

The WP Hardening ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the $_SERVER['REQUEST_URI'] before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue.

πŸ“– Read

via "National Vulnerability Database".
19:15
β€Ό CVE-2021-24369 β€Ό

In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Text input fields were not getting sanitized properly. So it was possible to inject malicious content such as img tags, leading to a Stored Cross-Site Scripting issue which is triggered when the form will be edited, for example when an admin reviews it and could lead to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
19:15
β€Ό CVE-2021-29061 β€Ό

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs.

πŸ“– Read

via "National Vulnerability Database".
19:22
❌ Wegmans Exposes Customer Data in Misconfigured Databases ❌

Cleanup in aisle "Oops": The supermarket chain said that it misconfigured two cloud databases, exposing customer data to public scrutiny.

πŸ“– Read

via "Threat Post".
?
20:04
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Did Companies Fail to Disclose Being Affected by SolarWinds Breach? πŸ•΄

The SEC has sent out letters to some investment firms and publicly listed companies seeking information, Reuters says.

πŸ“– Read

via "Dark Reading".
?
21:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2010-0413 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
21:15
β€Ό CVE-2021-32698 β€Ό

eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0.

πŸ“– Read

via "National Vulnerability Database".
22 June 2021
?
02:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-20742 β€Ό

Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.

πŸ“– Read

via "National Vulnerability Database".
02:15
β€Ό CVE-2021-20733 β€Ό

Improper authorization in handler for custom URL scheme vulnerability in ????????? (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

πŸ“– Read

via "National Vulnerability Database".
?
08:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Six Flags to Pay $36M Over Collection of Fingerprints ❌

Illinois Supreme Court rules in favor of class action against company’s practice of scanning people’s fingers when they enter amusement parks.

πŸ“– Read

via "Threat Post".
?
09:19
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-0571 β€Ό

In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possible access to restricted activities due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137395936

πŸ“– Read

via "National Vulnerability Database".
09:19
β€Ό CVE-2021-0563 β€Ό

In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172908358

πŸ“– Read

via "National Vulnerability Database".
?
11:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-0606 β€Ό

In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168034487

πŸ“– Read

via "National Vulnerability Database".
11:16
β€Ό CVE-2021-0545 β€Ό

In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258884

πŸ“– Read

via "National Vulnerability Database".
11:16
β€Ό CVE-2021-0539 β€Ό

In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-180419673

πŸ“– Read

via "National Vulnerability Database".
?
11:35
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Does Your Cyberattack Plan Include a Crisis Communications Strategy? 5 Tips to Get Started πŸ•΄

Don't overlook crisis communications in your cybersecurity incident response planning.

πŸ“– Read

via "Dark Reading".
11:44
⚠ Ransomware: What REALLY happens if you pay the crooks? ⚠

Free talk! Join us online for as much fun as you can ethically have while talking about ransomware. (And learn some useful stuff too!)

πŸ“– Read

via "Naked Security".
?
12:05
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ 7 Powerful Cybersecurity Skills the Energy Sector Needs Most πŸ•΄

Those looking to join the fight might want to polish up or acquire some (or all) of these hottest skills on the market.

πŸ“– Read

via "Dark Reading".
?
13:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-22168 β€Ό

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

πŸ“– Read

via "National Vulnerability Database".
13:16
β€Ό CVE-2021-34243 β€Ό

A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The exploit is triggered when a user visits the upload location of the crafted file.

πŸ“– Read

via "National Vulnerability Database".
13:16
β€Ό CVE-2020-22167 β€Ό

PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.

πŸ“– Read

via "National Vulnerability Database".
13:23
❌ Lexmark Printers Open to Arbitrary Code-Execution Zero-Day ❌

β€œNo remedy available as of June 21, 2021," according to the researcher who discovered the easy-to-exploit, no-user-action-required bug.

πŸ“– Read

via "Threat Post".
?
13:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Kids’ Apps on Google Play Rife with Privacy Violations ❌

One in five of the most-popular apps for kids under 13 on Google Play don't comply with COPPA regulations on how children's information is collected and used.

πŸ“– Read

via "Threat Post".
14:05
πŸ•΄ Majority of Web Apps in 11 Industries Are Vulnerable All the Time πŸ•΄

Serious vulnerabilities exist every day in certain industries, including utilities, public administration, and professional services, according to testing data.

πŸ“– Read

via "Dark Reading".
?
14:21
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Splunk launches security products and AWS security enhancements 🦿

The new offerings are aimed at integrating security data across multiple on-prem and cloud environments and vendors to improve cybersecurity decision-making, the company says.

πŸ“– Read

via "Tech Republic".
14:35
πŸ•΄ NSA Funds Development & Release of D3FEND Framework πŸ•΄

The framework, now available through MITRE, provides countermeasures to attacks.

πŸ“– Read

via "Dark Reading".
?
15:05
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Chart: Strength in Numbers πŸ•΄

More companies are heeding expert advice to beef up their incident-response teams.

πŸ“– Read

via "Dark Reading".
15:16
β€Ό CVE-2020-18654 β€Ό

Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".

πŸ“– Read

via "National Vulnerability Database".
15:23
❌ Email Bug Allows Message Snooping, Credential Theft ❌

A year-old proof-of-concept attack that allows an attacker to bypass TLS email protections to snoop on messages has been patched.

πŸ“– Read

via "Threat Post".
?
15:51
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How a Business Email Compromise attack can threaten your organization 🦿

The most common type of BEC campaign involves a spoofed email account or website, according to GreatHorn.

πŸ“– Read

via "Tech Republic".
16:05
πŸ•΄ Transmit Security Announces $543M Series A Funding Round πŸ•΄

The passwordless technology provider says the funding will be used to increase its reach and expand primary business functions.

πŸ“– Read

via "Dark Reading".
?
16:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Cryptominers Slither into Python Projects in Supply-Chain Campaign ❌

These code bombs lurk in the PyPI package repository, waiting to be inadvertently baked into software developers' applications.

πŸ“– Read

via "Threat Post".
17:04
πŸ›  Clam AntiVirus Toolkit 0.103.3 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

πŸ“– Read

via "Packet Storm Security".
17:16
β€Ό CVE-2021-22377 β€Ό

There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service.

πŸ“– Read

via "National Vulnerability Database".
17:16
β€Ό CVE-2021-22382 β€Ό

Huawei LTE USB Dongle products have an improper permission assignment vulnerability. An attacker can locally access and log in to a PC to induce a user to install a specially crafted application. After successfully exploiting this vulnerability, the attacker can perform unauthenticated operations. Affected product versions include:E3372 E3372h-153TCPU-V200R002B333D01SP00C00.

πŸ“– Read

via "National Vulnerability Database".
17:16
β€Ό CVE-2021-22361 β€Ό

There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200. A file access is not authorized correctly. Attacker with low access may launch privilege escalation in a specific scenario. This may compromise the normal service.

πŸ“– Read

via "National Vulnerability Database".
?
17:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ BEC Losses Top $1.8B as Tactics Evolve ❌

BEC attacks getting are more dangerous, and smart users are the ones who can stop it.

πŸ“– Read

via "Threat Post".
?
19:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32699 β€Ό

Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vulnerable to system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended and cause downstream impacts to other clients on the same hardware, eventually causing the physical server to stop responding. Users should upgrade to `1.4.4` to mitigate the issue. There is no non-code based workaround for impacted versions of the software. Users running customized versions of this software can manually set a PID limit for containers created.

πŸ“– Read

via "National Vulnerability Database".
19:16
β€Ό CVE-2021-32700 β€Ό

Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha 3 have a potential for a supply chain attack via MiTM against users. Http connections did not make use of TLS and certificate checking was ignored. The vulnerability allows an attacker to substitute or modify packages retrieved from BC thus allowing to inject malicious code into ballerina executables. This has been patched in Ballerina 1.2.14 and Ballerina SwanLake alpha4.

πŸ“– Read

via "National Vulnerability Database".
?
19:51
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Data resiliency is key to surviving a ransomware attack, expert says 🦿

It's not "if" but "when" you'll be attacked, cybersecurity expert says. Checking on your data and backups is something businesses should do regularly.

πŸ“– Read

via "Tech Republic".
19:51
🦿 How to be prepared for a ransomware attack: Check your data and backups 🦿

Expert says ransomware attacks will happen, and your company has to be prepared long before the attack hits.

πŸ“– Read

via "Tech Republic".
20:05
πŸ•΄ Despite Heightened Cyber-Risks, Few Security Leaders Report to CEO πŸ•΄

A new report suggests that top management at most companies still don't get security.

πŸ“– Read

via "Dark Reading".
?
21:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-34391 β€Ό

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel�s tz_handle_trusted_app_smc function where a lack of integer overflow checks on the req_off and param_ofs variables leads to memory corruption of critical kernel structures.

πŸ“– Read

via "National Vulnerability Database".
21:27
β€Ό CVE-2021-34396 β€Ό

Bootloader contains a vulnerability in access permission settings where unauthorized software may be able to overwrite NVIDIA MB2 code, which would result in limited denial of service.

πŸ“– Read

via "National Vulnerability Database".
21:27
β€Ό CVE-2021-34393 β€Ό

Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

πŸ“– Read

via "National Vulnerability Database".
21:27
β€Ό CVE-2021-34395 β€Ό

Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure and limited denial of service.

πŸ“– Read

via "National Vulnerability Database".
21:30
β€Ό CVE-2021-34397 β€Ό

Bootloader contains a vulnerability in NVIDIA MB2, which may cause free-the-wrong-heap, which may lead to limited denial of service.

πŸ“– Read

via "National Vulnerability Database".
21:30
β€Ό CVE-2021-34392 β€Ό

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the tz_map_shared_mem function can bypass boundary checks, which might lead to denial of service.

πŸ“– Read

via "National Vulnerability Database".
21:30
β€Ό CVE-2021-34390 β€Ό

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow on the size parameter of the tz_map_shared_mem function.

πŸ“– Read

via "National Vulnerability Database".
23 June 2021
?
07:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ SonicWall β€˜Botches’ October Patch for Critical VPN Bug ❌

Company finally rolls out the complete fix this week for an RCE flaw affecting some 800,000 devices that could result in crashes or prevent users from connecting to corporate resources.

πŸ“– Read

via "Threat Post".
?
09:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-35210 β€Ό

Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.

πŸ“– Read

via "National Vulnerability Database".
09:17
β€Ό CVE-2021-29084 β€Ό

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
09:23
❌ Unpatched Linux Marketplace Bugs Allow Wormable Attacks, Drive-By RCE ❌

A pair of zero-days affecting Pling-based marketplaces could allow for some ugly attacks on unsuspecting Linux enthusiasts -- with no patches in sight.

πŸ“– Read

via "Threat Post".
?
11:05
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Expecting the Unexpected: Tips for Effectively Mitigating Ransomware Attacks in 2021 πŸ•΄

Cybercriminals continually innovate to thwart security protocols, but organizations can take steps to prevent and mitigate ransomware attacks.

πŸ“– Read

via "Dark Reading".
?
11:52
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How to better detect and prevent Business Email Compromise attacks 🦿

These types of email attacks rely on simple language and exploit human nature to scam their victims, making detection difficult, says Cisco Talos.

πŸ“– Read

via "Tech Republic".
?
12:23
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ REvil Ransomware Code Ripped Off by Rivals ❌

The LV ransomware operators likely used a hex editor to repurpose a REvil binary almost wholesale, for their own nefarious purposes.

πŸ“– Read

via "Threat Post".
?
12:52
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Employees are valuable assets: Why you need to safeguard them 🦿

Two experts suggest calling employees "insider threats" is counterproductive; employees are assets needing protection.

πŸ“– Read

via "Tech Republic".
12:55
❌ Critical Palo Alto Cyber-Defense Bug Allows Remote β€˜War Room’ Access ❌

Remote, unauthenticated cyberattackers can infiltrate and take over the Cortex XSOAR platform, which anchors unified threat intelligence and incident responses.

πŸ“– Read

via "Threat Post".
?
13:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-25950 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
13:17
β€Ό CVE-2020-20391 β€Ό

Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.

πŸ“– Read

via "National Vulnerability Database".
13:17
β€Ό CVE-2011-1955 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
13:20
πŸ” An Interview with Ben McGraw, Cybersecurity Manager at Digital Guardian Part I πŸ”

In part one of our Q&A with Ben McGraw, we discuss his journey to Digital Guardian, insight from DG's Analytics & Reporting Cloud, and what makes a good threat hunter.

πŸ“– Read

via "".
13:23
🦿 Cybersecurity practices must be applied to vehicles, too 🦿

Manufacturers want to pack cars and trucks full of technology, but they need to remember the dangers to those who drive or ride in them.

πŸ“– Read

via "Tech Republic".
?
14:05
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ When Will Cybersecurity Operations Adopt the Peter Parker Principle? πŸ•΄

Having a prevention mindset means setting our prevention capabilities to "prevent" instead of relying on detection and response.

πŸ“– Read

via "Dark Reading".
?
14:23
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Pandemic-Bored Attackers Pummeled Gaming Industry ❌

Akamai's 2020 gaming report shows that cyberattacks on the video game industry skyrocketed, shooting up 340 percent in 2020.

πŸ“– Read

via "Threat Post".
?
15:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-3526 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
15:17
β€Ό CVE-2021-33624 β€Ό

In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.

πŸ“– Read

via "National Vulnerability Database".
?
16:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Iran Media Websites Seized by U.S. in Disinformation Campaign ❌

DoJ uses sanctions laws to shut down an alleged Iranian government malign influence campaign.

πŸ“– Read

via "Threat Post".
17:06
πŸ•΄ Survey Seeks to Learn How 2020 Changed Security πŸ•΄

Respondents to a new Dark Reading/Omdia survey will be entered into a drawing for a Black Hat Black Card.

πŸ“– Read

via "Dark Reading".
17:06
πŸ•΄ New DNS Name Server Hijack Attack Exposes Businesses, Government Agencies πŸ•΄

Researchers found a "novel" class of DNS vulnerabilities in AWS Route53 and other DNS-as-a-service offerings that leak sensitive information on corporate and government customers, with one simple registration step.

πŸ“– Read

via "Dark Reading".
17:17
β€Ό CVE-2020-18657 β€Ό

Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.

πŸ“– Read

via "National Vulnerability Database".
?
17:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Microsoft Tracks New BazaCall Malware Campaign πŸ•΄

Attackers use emails to prompt victims to call a fraudulent call center, where attackers instruct them to download a malicious file.

πŸ“– Read

via "Dark Reading".
?
19:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-18660 β€Ό

GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.

πŸ“– Read

via "National Vulnerability Database".
?
19:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ VMs Help Ransomware Attackers Evade Detection, But It's Uncommon πŸ•΄

Some ransomware attackers use virtual machines to bypass security detection, but adoption is slow for the complicated technique.

πŸ“– Read

via "Dark Reading".
?
20:06
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ 79% of Third-Party Libraries in Apps Are Never Updated πŸ•΄

A lack of contextual information and concerns over application disruption among contributing factors.

πŸ“– Read

via "Dark Reading".
?
21:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-21809 β€Ό

A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

πŸ“– Read

via "National Vulnerability Database".
24 June 2021
?
02:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32823 β€Ό

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

πŸ“– Read

via "National Vulnerability Database".
02:18
β€Ό CVE-2021-35041 β€Ό

The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A malicious node can send a packet continuously. The packet is in an incorrect format and cannot be decoded by the node correctly. As a result, the node may consume the memory sustainably and crash. More details are shown at: https://github.com/FISCO-BCOS/FISCO-BCOS/issues/1951

πŸ“– Read

via "National Vulnerability Database".
?
07:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-25652 β€Ό

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects versions 8.0.0.0 through 8.1.3.1 of AVPU.

πŸ“– Read

via "National Vulnerability Database".
07:18
β€Ό CVE-2021-25655 β€Ό

A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).

πŸ“– Read

via "National Vulnerability Database".
07:24
❌ 30M Dell Devices at Risk for Remote BIOS Attacks, RCE ❌

Four separate security bugs would give attackers almost complete control and persistence over targeted devices, thanks to a faulty update mechanism.

πŸ“– Read

via "Threat Post".
07:24
❌ Atlassian Bugs Could Have Led to 1-Click Takeover ❌

A supply-chain attack could have siphoned sensitive information out of Jira, such as security issues on Atlassian cloud, Bitbucket and on-prem products.

πŸ“– Read

via "Threat Post".
?
09:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-21737 β€Ό

A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10 B860H V5.0, V83011303.0010, V83011303.0016

πŸ“– Read

via "National Vulnerability Database".
?
09:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ rMTD: A Deception Method That Throws Attackers Off Their Game πŸ•΄

Through a variety of techniques, rotational Moving Target Defense makes existing OS and app vulnerabilities exponentially difficult to exploit. Here's how.

πŸ“– Read

via "Dark Reading".
?
10:24
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Tulsa’s Police-Citation Data Leaked by Conti Gang ❌

A May 6 ransomware attack caused disruption across several of the municipality’s online services and websites.

πŸ“– Read

via "Threat Post".
?
11:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ John McAfee, Creator of McAfee Antivirus Software, Dead at 75 πŸ•΄

McAfee, who was being held in a Spanish jail on US tax-evasion charges, had learned on Monday he would be extradited to the US.

πŸ“– Read

via "Dark Reading".
11:11
πŸ•΄ Storms & Silver Linings: Avoiding the Dangers of Cloud Migration πŸ•΄

We hear a lot about the sunlit uplands of cloud-powered business, but what about the risks of making information available across the organization?

πŸ“– Read

via "Dark Reading".
11:18
β€Ό CVE-2021-26585 β€Ό

A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32.

πŸ“– Read

via "National Vulnerability Database".
11:18
β€Ό CVE-2020-28097 β€Ό

The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85.

πŸ“– Read

via "National Vulnerability Database".
?
12:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Remote Access Trojan now targeting schools with ransomware 🦿

Dubbed ChaChi by researchers at BlackBerry, the RAT has recently shifted its focus from government agencies to schools in the US.

πŸ“– Read

via "Tech Republic".
?
12:44
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ S3 Ep38: Clop busts, destructive Linux hacking, and rooted bicycles [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
12:54
❌ Critical VMware Carbon Black Bug Allows Authentication Bypass ❌

The 9.4-rated bug in AppC could give attackers admin rights, no authentication required, letting them attack anything from PoS to industrial control systems.

πŸ“– Read

via "Threat Post".
?
13:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-24000 β€Ό

A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as &lt;input type="file"&gt;) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not intend to. This vulnerability affects Firefox < 88.

πŸ“– Read

via "National Vulnerability Database".
13:18
β€Ό CVE-2021-29963 β€Ό

Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.

πŸ“– Read

via "National Vulnerability Database".
13:24
β€Ό CVE-2021-29953 β€Ό

A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resulting in a Universal Cross-Site Scripting vulnerability. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected. Further details are being temporarily withheld to allow users an opportunity to update.*. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.

πŸ“– Read

via "National Vulnerability Database".
13:24
β€Ό CVE-2020-21787 β€Ό

CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

πŸ“– Read

via "National Vulnerability Database".
?
14:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Boardroom Perspectives on Cybersecurity: What It Means for You πŸ•΄

Because board members are paying close attention to security, security leaders must be able to respond to and alleviate their concerns with data.

πŸ“– Read

via "Dark Reading".
?
15:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-18664 β€Ό

Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.

πŸ“– Read

via "National Vulnerability Database".
15:18
β€Ό CVE-2020-21783 β€Ό

In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter.

πŸ“– Read

via "National Vulnerability Database".
15:18
β€Ό CVE-2021-32708 β€Ό

Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely. The conditions are: A user is allowed to supply the path or filename of an uploaded file, the supplied path or filename is not checked against unicode chars, the supplied pathname checked against an extension deny-list, not an allow-list, the supplied path or filename contains a unicode whitespace char in the extension, the uploaded file is stored in a directory that allows PHP code to be executed. Given these conditions are met a user can upload and execute arbitrary code on the system under attack. The unicode whitespace removal has been replaced with a rejection (exception). For 1.x users, upgrade to 1.1.4. For 2.x users, upgrade to 2.1.1.

πŸ“– Read

via "National Vulnerability Database".
?
15:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Preinstalled Firmware Updater Puts 128 Dell Models at Risk πŸ•΄

A feature of the computer maker's update utility does not correctly handle certificates, leaving systems open to firmware-level compromises.

πŸ“– Read

via "Dark Reading".
?
16:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How to easily join an AlmaLinux server to an Active Directory Domain with Cockpit 🦿

Jack Wallen shows you just how easy it is to join an existing AlmaLinux server to an Active Directory domain via a web-based GUI.

πŸ“– Read

via "Tech Republic".
16:36
πŸ•΄ Tulsa Officials Warn Ransomware Attackers Leaked City Files πŸ•΄

The group behind the May 2021 attack has shared more than 18,000 files via the Dark Web, mostly internal department files and police citations.

πŸ“– Read

via "Dark Reading".
?
16:54
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Oh FCUK! Fashion Label, Medical Diagnostics Firm Latest REvil Victims ❌

The infamous ransomware group hit two big-name companies within hours of each other. Β 

πŸ“– Read

via "Threat Post".
?
17:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32491 β€Ό

A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.

πŸ“– Read

via "National Vulnerability Database".
17:18
β€Ό CVE-2020-4945 β€Ό

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.

πŸ“– Read

via "National Vulnerability Database".
17:21
πŸ” First CCPA Rights Requests Deadline Looms πŸ”

Organizations that comply with the CCPA should be aware of an upcoming public reporting requirement deadline, one of the first deadlines under the relatively new law.

πŸ“– Read

via "".
?
19:06
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ 74% of Q1 Malware Was Undetectable Via Signature-Based Tools πŸ•΄

Attackers have improved on tweaking old malware to continue sneaking it past traditional threat detection controls, researchers report.

πŸ“– Read

via "Dark Reading".
19:18
β€Ό CVE-2021-32716 β€Ό

Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.

πŸ“– Read

via "National Vulnerability Database".
19:18
β€Ό CVE-2021-32711 β€Ό

Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by this change. We recommend to update to the current version 6.3.5.1. You can get the update to 6.3.5.1 regularly via the Auto-Updater or directly via the download overview. https://www.shopware.com/en/download/#shopware-6 The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by this change. Please check your plugins if you have it in use. Detailed technical information can be found in the upgrade information. https://github.com/shopware/platform/blob/v6.3.5.1/UPGRADE-6.3.md#6351 ### Workarounds For older versions of 6.1 and 6.2, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version. https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659 ### For more information https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-02-2021

πŸ“– Read

via "National Vulnerability Database".
?
22:24
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Spam Downpour Drips New IcedID Banking Trojan Variant ❌

The primarily IcedID-flavored banking trojan spam campaigns were coming in at a fever pitch: Spikes hit more than 100 detections a day.

πŸ“– Read

via "Threat Post".
25 June 2021
?
09:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ British tourists charged £1000s for pier visits in billing blunder ⚠

That's a LOT of money just to visit a seaside pier!

πŸ“– Read

via "Naked Security".
09:19
β€Ό CVE-2021-35475 β€Ό

SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.

πŸ“– Read

via "National Vulnerability Database".
?
10:25
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Hackers Crack Pirated Games with Cryptojacking Malware ❌

Threat actors have so far made about $2 million from Crackonosh, which secretly mines Monero cryptocurrency from affected devices.

πŸ“– Read

via "Threat Post".
?
11:07
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ 7 Unconventional Pieces of Password Wisdom πŸ•΄

Challenging common beliefs about best practices in password hygiene.

πŸ“– Read

via "Dark Reading".
11:19
β€Ό CVE-2021-31615 β€Ό

Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a crafted packet during the receive window of the listening device before the transmitting device initiates its packet transmission to achieve full MITM status without terminating the link. When applied against devices establishing or using encrypted links, crafted packets may be used to terminate an existing link, but will not compromise the confidentiality or integrity of the link.

πŸ“– Read

via "National Vulnerability Database".
11:19
β€Ό CVE-2021-35049 β€Ό

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
?
12:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ High-Level FIN7 Member Sentenced to 7 Years in Prison πŸ•΄

Andrii Kolpakov, who served as a high-level pentester for the criminal group, was also ordered to pay $2.5 million in restitution.

πŸ“– Read

via "Dark Reading".
?
12:55
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ My Book Live Users Wake Up to Wiped Devices, Active RCE Attacks ❌

β€œI am totally screwed,” one user wailed after finding years of data nuked. Western Digital advised yanking the NAS storage devices offline ASAP: There's an exploit.

πŸ“– Read

via "Threat Post".
13:07
πŸ•΄ School's Out for Summer, but Don't Close the Book on Cybersecurity Training πŸ•΄

Strengthening their security posture should be at the top of school IT departments' summer to-do list.

πŸ“– Read

via "Dark Reading".
13:19
β€Ό CVE-2021-34184 β€Ό

Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h.

πŸ“– Read

via "National Vulnerability Database".
13:25
❌ Cisco ASA Bug Now Actively Exploited as PoC Drops ❌

In-the-wild XSS attacks have commenced against the security appliance (CVE-2020-3580), as researchers publish exploit code on Twitter.

πŸ“– Read

via "Threat Post".
13:36
πŸ›  Flawfinder 2.0.18 πŸ› 

Flawfinder searches through source code for potential security flaws, listing potential security flaws sorted by risk, with the most potentially dangerous flaws shown first. This risk level depends not only on the function, but on the values of the parameters of the function.

πŸ“– Read

via "Packet Storm Security".
?
14:20
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ” Friday Five 6/25 πŸ”

Ransomware debates, spyware indictments, and CISA confirmations- catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "".
?
15:07
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Data Privacy Is in 23andMe CSO's DNA πŸ•΄

How serious is the company about safeguarding its customers and their genetic information? "We're hiding data even from ourselves," says the biotech and genetic testing company's head of security.

πŸ“– Read

via "Dark Reading".
15:19
β€Ό CVE-2021-3314 β€Ό

** UNSUPPORTED WHEN ASSIGNED ** Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“– Read

via "National Vulnerability Database".
15:19
β€Ό CVE-2021-35501 β€Ό

PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.

πŸ“– Read

via "National Vulnerability Database".
15:25
❌ FIN7 β€˜Pen Tester’ Headed to Jail Amid $1B in Payment-Card Losses ❌

One of the Carbanak cybergang's highest-level hackers is destined to serve seven years while making $2.5 million in restitution payments.

πŸ“– Read

via "Threat Post".
?
16:53
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Ransomware-as-a-service business model takes a hit in the aftermath of the Colonial Pipeline attack 🦿

Cybercrime gangs are finding it harder to recruit partners for the affiliate programs that power ransomware attacks.

πŸ“– Read

via "Tech Republic".
?
17:19
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-33529 β€Ό

In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the device.

πŸ“– Read

via "National Vulnerability Database".
17:19
β€Ό CVE-2021-33532 β€Ό

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
17:19
β€Ό CVE-2021-33542 β€Ό

Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialized data. The attacker needs to get access to an original bus configuration file (*.bcp) to be able to manipulate data inside. After manipulation the attacker needs to exchange the original file by the manipulated one on the application programming workstation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities. Automated systems in operation which were programmed with one of the above-mentioned products are not affected.

πŸ“– Read

via "National Vulnerability Database".
?
18:23
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Linux: How to find details about user logins 🦿

If you need to gather information on user logins for your Linux servers, Jack Wallen has just the tool for you.

πŸ“– Read

via "Tech Republic".
18:25
❌ PS3 Players Ban: Latest Victims of Surging Attacks on Gaming Industry   ❌

Every Sony PlayStation 3 ID out there was compromised, provoking bans of legit players on the network.

πŸ“– Read

via "Threat Post".
18:37
πŸ•΄ New CPU Baseline for Windows 11 Will Ensure Better Security, Microsoft Says πŸ•΄

Redmond's latest OS will run only on systems with TPM 2.0 chips.

πŸ“– Read

via "Dark Reading".
?
18:55
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Mercedes-Benz Customer Data Flies Out the Window ❌

For over three years, a vendor was recklessly driving the cloud-stored data of luxury-car-owning customers and wannabe buyers.

πŸ“– Read

via "Threat Post".
?
19:19
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-35502 β€Ό

app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.

πŸ“– Read

via "National Vulnerability Database".
19:19
β€Ό CVE-2021-25654 β€Ό

An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.

πŸ“– Read

via "National Vulnerability Database".
19:19
β€Ό CVE-2021-1073 β€Ό

NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability where, if a user clicks on a maliciously formatted link that opens the GeForce Experience login page in a new browser tab instead of the GeForce Experience application and enters their login information, the malicious site can get access to the token of the user login session. Such an attack may lead to these targeted users' data being accessed, altered, or lost.

πŸ“– Read

via "National Vulnerability Database".
27 June 2021
?
11:21
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-35513 β€Ό

Mermaid before 8.11.0 allows XSS when the antiscript feature is used.

πŸ“– Read

via "National Vulnerability Database".
28 June 2021
?
02:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-20751 β€Ό

Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.

πŸ“– Read

via "National Vulnerability Database".
02:22
β€Ό CVE-2021-20745 β€Ό

Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop.

πŸ“– Read

via "National Vulnerability Database".
02:22
β€Ό CVE-2021-20749 β€Ό

Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7.0 and earlier, and Fudousan Plugin Pro Multi-User Type ver5.7.0 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
?
07:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-23399 β€Ό

This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

πŸ“– Read

via "National Vulnerability Database".
?
09:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-20099 β€Ό

Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021-20100.

πŸ“– Read

via "National Vulnerability Database".
09:22
β€Ό CVE-2021-20100 β€Ό

Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021-20099.

πŸ“– Read

via "National Vulnerability Database".
09:25
🦿 Cybersecurity study: SolarWinds attack cost affected US companies an average of $12 million 🦿

New survey finds that the attack also motivated more information sharing within the industry and improved supply chain security.

πŸ“– Read

via "Tech Republic".
?
11:09
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ The Role of Encryption in Protecting LGBTQ+ Community Members πŸ•΄

The Internet is a vital tool that helps LGBTQ+ community members communicate without fear of persecution -- and strong encryption is a critical part of this equation.

πŸ“– Read

via "Dark Reading".
?
11:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32496 β€Ό

SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concerning the internal SSH interface solely used by SICK for recovering returned devices. The use of weak ciphers make it easier for an attacker to break the security that protects information transmitted from the client to the SSH server, assuming the attacker has access to the network on which the device is connected. This can increase the risk that encryption will be compromised, leading to the exposure of sensitive user information and man-in-the-middle attacks.

πŸ“– Read

via "National Vulnerability Database".
11:27
β€Ό CVE-2021-29157 β€Ό

Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.

πŸ“– Read

via "National Vulnerability Database".
?
12:24
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Android: How to enable the Password Checkup feature 🦿

Google has released a new password checker for Android. Find out how to enable and use this security feature on your Android device.

πŸ“– Read

via "Tech Republic".
?
13:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Critical CISO Initiatives for the Second Half of 2021 ❌

Saryu Nayyar, CEO at Gurucul, goes over what defenses CISOs need now, and how and why to prioritize the options.

πŸ“– Read

via "Threat Post".
13:27
β€Ό CVE-2021-28570 β€Ό

Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.

πŸ“– Read

via "National Vulnerability Database".
13:27
β€Ό CVE-2021-21090 β€Ό

Adobe InCopy version 16.0 (and earlier) is affected by an path traversal vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
13:27
β€Ό CVE-2021-28575 β€Ό

Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
?
13:54
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How developing mental immunity can help you make better cybersecurity decisions 🦿

Experts want us to develop immunity to bad ideas that can wrongly influence the cybersecurity decision process.

πŸ“– Read

via "Tech Republic".
13:57
❌ Microsoft Signs Malware That Spreads Through Gaming ❌

The driver, called "Netfilter," is a rootkit that talks to Chinese C2 IPs and aims to spoof gamers' geo-locations to cheat the system and play from anywhere, Microsoft said.

πŸ“– Read

via "Threat Post".
?
15:09
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ The Danger of Action Bias: Is It Always Better to Act Quickly? πŸ•΄

Experts discuss the meaning of action bias and how it presents a threat to IT security leaders, practitioners, and users.

πŸ“– Read

via "Dark Reading".
?
15:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32719 β€Ό

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

πŸ“– Read

via "National Vulnerability Database".
15:27
β€Ό CVE-2021-20494 β€Ό

IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bounds. An authenticared user could overflow the buffer and cause the service to crash. IBM X-Force ID: 197882.

πŸ“– Read

via "National Vulnerability Database".
15:27
β€Ό CVE-2020-23711 β€Ό

SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.

πŸ“– Read

via "National Vulnerability Database".
15:27
β€Ό CVE-2021-20572 β€Ό

IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199247.

πŸ“– Read

via "National Vulnerability Database".
?
16:09
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ An Interesting Approach to Cyber Insurance πŸ•΄

What if insurers were to offer companies an incentive -- say, a discount -- for better protecting themselves? You know, the way car insurance companies offer lower premiums to customers who take a driver's ed course.

πŸ“– Read

via "Dark Reading".
?
16:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Russian Attackers Breach Microsoft Customer Service Accounts ❌

American IT companies and government have been targeted by the Nobelium state-sponsored group. Β 

πŸ“– Read

via "Threat Post".
?
16:54
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Cybersecurity study: SolarWinds attack cost affected companies an average of $12 million 🦿

New survey finds that the attack also motivated more information sharing within the industry and improved supply chain security.

πŸ“– Read

via "Tech Republic".
?
17:09
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Microsoft Tracks Attack Campaign Against Customer Support Agents πŸ•΄

The company attributes the attack to Nobelium, the same group it linked to the SolarWinds campaign earlier this year.

πŸ“– Read

via "Dark Reading".
?
17:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-22607 β€Ό

Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php.

πŸ“– Read

via "National Vulnerability Database".
17:27
β€Ό CVE-2020-22609 β€Ό

Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.

πŸ“– Read

via "National Vulnerability Database".
17:39
πŸ•΄ New House Bill Aims to Drive Americans' Security Awareness πŸ•΄

The legislation requires the National Telecommunications and Information Administration to establish a cybersecurity literacy campaign.

πŸ“– Read

via "Dark Reading".
?
17:57
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ NVIDIA Patches High-Severity GeForce Spoof-Attack Bug ❌

A vulnerability in NVIDIA’s GeForce Experience software opens the door to remote data access, manipulation and deletion.

πŸ“– Read

via "Threat Post".
?
18:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ” Data Protection Act of 2021 Would Create US Data Protection Agency πŸ”

The proposed legislation would create an agency to enforce data protection rules and oversee high-risk data practices.

πŸ“– Read

via "".
18:27
❌ 5G Security Vulnerabilities Fluster Mobile Operators ❌

A survey from GSMA and Trend Micro shows a concerning lack of security capabilities for private 5G networks (think factories, smart cities, industrial IoT, utilities and more).

πŸ“– Read

via "Threat Post".
18:39
πŸ•΄ Attacks Erase Western Digital Network-Attached Storage Drives πŸ•΄

The company suspects a remote code execution vulnerability affecting My Book Live and My Book Live Duo devices and recommends that business and individual users turn off the drives to protect their data.

πŸ“– Read

via "Dark Reading".
?
19:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-21142 β€Ό

Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.

πŸ“– Read

via "National Vulnerability Database".
19:27
β€Ό CVE-2021-35298 β€Ό

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.

πŸ“– Read

via "National Vulnerability Database".
19:28
β€Ό CVE-2021-35302 β€Ό

Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
19:28
β€Ό CVE-2021-32722 β€Ό

GlobalNewFiles is a mediawiki extension. All existing versions of GlobalNewFiles are affected by an uncontrolled resource consumption vulnerability. A large amount of page moves within a short space of time could overwhelm Database servers due to improper handling of load balancing and a lack of an appropriate index. No patches are currently available. As a workaround, one may avoid use of the extension unless additional rate limit at the MediaWiki level or via PoolCounter / MySQL is enabled.

πŸ“– Read

via "National Vulnerability Database".
19:28
β€Ό CVE-2021-35303 β€Ό

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute.

πŸ“– Read

via "National Vulnerability Database".
19:28
β€Ό CVE-2021-32723 β€Ό

Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCIIDoc or ERB to highlight untrusted text. Other languages are not affected and can be used to highlight untrusted text.

πŸ“– Read

via "National Vulnerability Database".
19:28
β€Ό CVE-2021-35301 β€Ό

Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.

πŸ“– Read

via "National Vulnerability Database".
19:28
β€Ό CVE-2021-35299 β€Ό

Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.

πŸ“– Read

via "National Vulnerability Database".
19:28
β€Ό CVE-2021-35300 β€Ό

Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.

πŸ“– Read

via "National Vulnerability Database".
19:39
πŸ•΄ Microsoft Refining Third-Party Driver Vetting Processes After Signing Malicious Rootkit πŸ•΄

Rogue driver was distributed within gaming community in China, company says.

πŸ“– Read

via "Dark Reading".
?
20:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground ❌

After 500 million LinkedIn enthusiasts were affected in a data-scraping incident in April, it's happened again - with big security ramifications.

πŸ“– Read

via "Threat Post".
29 June 2021
?
02:28
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-1134 β€Ό

A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation of the X.509 certificate used when establishing a connection between DNA Center and an ISE server. An attacker could exploit this vulnerability by supplying a crafted certificate and could then intercept communications between the ISE and DNA Center. A successful exploit could allow the attacker to view and alter sensitive information that the ISE maintains about clients that are connected to the network.

πŸ“– Read

via "National Vulnerability Database".
?
06:27
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Cobalt Strike Usage Explodes Among Cybercrooks ❌

The legit security tool has shown up 161 percent more, year-over-year, in cyberattacks, having β€œgone fully mainstream in the crimeware world.”

πŸ“– Read

via "Threat Post".
?
08:57
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Details of RCE Bug in Adobe Experience Manager Revealed ❌

Disclosure of a bug in Adobe’s content-management solution - used by Mastercard, LinkedIn and PlayStation – were released.

πŸ“– Read

via "Threat Post".
?
09:28
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-33503 β€Ό

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

πŸ“– Read

via "National Vulnerability Database".
09:28
β€Ό CVE-2021-34548 β€Ό

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

πŸ“– Read

via "National Vulnerability Database".
?
10:54
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Americans lost $29.8 billion to phone scams in the past year, study finds 🦿

The number of spam calls, the number of people losing money to them and the total amount of money lost In the past year are all record setting.

πŸ“– Read

via "Tech Republic".
?
11:10
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ 3 Ways Cybercriminals Are Undermining MFA πŸ•΄

Using multifactor authentication is an excellent security step, but like everything else, it is not foolproof and will never be 100% effective.

πŸ“– Read

via "Dark Reading".
?
11:28
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-23400 β€Ό

The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.

πŸ“– Read

via "National Vulnerability Database".
11:28
β€Ό CVE-2020-7871 β€Ό

A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of the parameter. This issue affects: Cnesty Helpcom 10.0 versions prior to.

πŸ“– Read

via "National Vulnerability Database".
?
12:25
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Security and automation are top priorities for IT professionals 🦿

Data protection and lack of budgets and resources continue to present the biggest challenges as cyberattacks increase, according to a new Kaseya report.

πŸ“– Read

via "Tech Republic".
?
13:09
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ›  Proxmark 4.13441 πŸ› 

This is a custom firmware written for the Proxmark3 device. It extends the currently available firmware.

πŸ“– Read

via "Packet Storm Security".
?
13:28
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-7868 β€Ό

A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.

πŸ“– Read

via "National Vulnerability Database".
13:28
β€Ό CVE-2021-32992 β€Ό

FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory buffer, which may allow an attacker to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
13:28
β€Ό CVE-2021-31505 β€Ό

This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-12890.

πŸ“– Read

via "National Vulnerability Database".
13:28
β€Ό CVE-2020-7870 β€Ό

A memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to insufficient validation of the parameter.

πŸ“– Read

via "National Vulnerability Database".
?
13:55
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How to give users sudo privileges on Ubuntu and Red Hat-based Linux distributions in Linux 🦿

New Linux admins need to know how to give and take sudo privileges from users. Jack Wallen shows you how on both Ubuntu- and Red Hat-based Linux distributions.

πŸ“– Read

via "Tech Republic".
13:58
❌ Microsoft Translation Bugs Open Edge Browser to Trivial UXSS Attacks ❌

The bug in Edge's auto-translate could have let remote attackers pull off RCE on any foreign-language website just by sending a message with an XSS payload.

πŸ“– Read

via "Threat Post".
?
14:40
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Technology's Complexity and Opacity Threaten Critical Infrastructure Security πŸ•΄

Addressing the complexity of modern distributed software development is one of the most important things we can do to decrease supply chain risk.

πŸ“– Read

via "Dark Reading".
?
15:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-20104 β€Ό

Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.

πŸ“– Read

via "National Vulnerability Database".
15:29
β€Ό CVE-2021-20105 β€Ό

Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.

πŸ“– Read

via "National Vulnerability Database".
15:29
β€Ό CVE-2021-20580 β€Ό

IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 198241.

πŸ“– Read

via "National Vulnerability Database".
15:40
πŸ•΄ Survey Data Reveals Gap in Americans' Security Awareness πŸ•΄

Survey data reveals many people have never heard of major cyberattacks, including the attack targeting Colonial Pipeline.

πŸ“– Read

via "Dark Reading".
15:55
🦿 How legitimate security tool Cobalt Strike is being used in cyberattacks 🦿

Normally used by organizations for penetration testing, Cobalt Strike is exploited by cybercriminals to launch attacks, says Proofpoint.

πŸ“– Read

via "Tech Republic".
15:55
🦿 Cyberattacks and ransomware are no longer burglary; they're home invasion, expert says 🦿

More than 3.5 million people worldwide are needed to play defense against cyberattacks.

πŸ“– Read

via "Tech Republic".
?
16:40
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ CISA Publishes Catalog of Poor Security Practices πŸ•΄

Organizations often focus on promoting best practices, CISA says, but stopping poor security practices is equally important.

πŸ“– Read

via "Dark Reading".
?
16:58
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Users Clueless About Cybersecurity Risks: Study ❌

The return to offices, coupled with uninformed users (including IT pros) has teed up an unprecedented risk of enterprise attack.

πŸ“– Read

via "Threat Post".
?
17:25
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 iOS 15: How to enable Mail Privacy Protection 🦿

If you have access to Apple's iOS 15 Developer Beta, learn how to use an important security feature called Mail Privacy Protection.

πŸ“– Read

via "Tech Republic".
17:29
β€Ό CVE-2021-32721 β€Ό

PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to craft phishing links and other open redirects by exploiting the trailing slash redirection feature. This may lead to users being redirected to untrusted sites after following an attacker crafted link. The issue is resolved in v1.1.1. There are no existing workarounds.

πŸ“– Read

via "National Vulnerability Database".
17:29
β€Ό CVE-2021-22338 β€Ό

There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.

πŸ“– Read

via "National Vulnerability Database".
17:29
β€Ό CVE-2021-23275 β€Ό

The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Statistics Services, TIBCO Spotfire Statistics Services, and TIBCO Spotfire Statistics Services contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition: versions 1.2.4 and below, TIBCO Enterprise Runtime for R - Server Edition: versions 1.3.0 and 1.3.1, TIBCO Enterprise Runtime for R - Server Edition: versions 1.4.0, 1.5.0, and 1.6.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions 11.3.0 and below, TIBCO Spotfire Server: versions 10.3.12 and below, TIBCO Spotfire Server: versions 10.4.0, 10.5.0, 10.6.0, 10.6.1, 10.7.0, 10.8.0, 10.8.1, 10.9.0, 10.10.0, 10.10.1, 10.10.2, 10.10.3, and 10.10.4, TIBCO Spotfire Server: versions 11.0.0, 11.1.0, 11.2.0, and 11.3.0, TIBCO Spotfire Statistics Services: versions 10.3.0 and below, TIBCO Spotfire Statistics Services: versions 10.10.0, 10.10.1, and 10.10.2, and TIBCO Spotfire Statistics Services: versions 11.1.0, 11.2.0, and 11.3.0.

πŸ“– Read

via "National Vulnerability Database".
17:29
β€Ό CVE-2021-29480 β€Ό

Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the client side session module uses the application startup time as the signing key by default. This means that if an attacker can determine this time, and if encryption is not also used (which is recommended, but is not on by default), the session data could be tampered with by someone with the ability to write cookies. The default configuration is unsuitable for production use as an application restart renders all sessions invalid and is not multi-host compatible, but its use is not actively prevented. As of Ratpack 1.9.0, the default value is a securely randomly generated value, generated at application startup time. As a workaround, supply an alternative signing key, as per the documentation's recommendation.

πŸ“– Read

via "National Vulnerability Database".
?
18:40
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Ransomware Losses Drive Up Cyber-Insurance Costs πŸ•΄

Premiums have gone up by 7% on average for small firms and between 10% and 40% for medium and large businesses.

πŸ“– Read

via "Dark Reading".
?
19:10
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Google Updates Vulnerability Data Format to Support Automation πŸ•΄

The Open Source Vulnerability schema supports automated vulnerability handling in Go, Rust, Python, and Distributed Weakness Filing system, and it could be the favored format for future exporting of data.

πŸ“– Read

via "Dark Reading".
?
19:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-22329 β€Ό

There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be applied and affect integrity of the device. Affected product versions include:S12700 V200R007C01,V200R007C01B102,V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10;S1700 V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10;S2700 V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10;S5700 V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10,V200R011C10SPC100;S6700 V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10,V200R011C10SPC100;S7700 V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10;S9700 V200R007C01,V200R007C01B102,V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10.

πŸ“– Read

via "National Vulnerability Database".
19:29
β€Ό CVE-2021-22341 β€Ό

There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected product versions include:IPS Module V500R005C00SPC100,V500R005C00SPC200;NGFW Module V500R005C00SPC100,V500R005C00SPC200;NIP6300 V500R005C00SPC100,V500R005C10SPC200;NIP6600 V500R005C00SPC100,V500R005C00SPC200;Secospace USG6300 V500R005C00SPC100,V500R005C00SPC200;Secospace USG6500 V500R005C00SPC100,V500R005C10SPC200;Secospace USG6600 V500R005C00SPC100,V500R005C00SPC200.

πŸ“– Read

via "National Vulnerability Database".
30 June 2021
?
02:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-35959 β€Ό

In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.

πŸ“– Read

via "National Vulnerability Database".
?
06:25
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Windows 11: Understanding the system requirements and the security benefits 🦿

Security is a big part of Windows 11, but so is delivering productivity and a good experience with all the security features turned on.

πŸ“– Read

via "Tech Republic".
?
07:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32566 β€Ό

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

πŸ“– Read

via "National Vulnerability Database".
07:29
β€Ό CVE-2021-35474 β€Ό

Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

πŸ“– Read

via "National Vulnerability Database".
?
09:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ Police warn of WhatsApp scams in time for Social Media Day ⚠

Happy Social Media Day! Make it a day to review whether your social media security really is up to scratch.

πŸ“– Read

via "Naked Security".
09:29
β€Ό CVE-2021-34383 β€Ό

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might lead to denial of service or escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
09:29
β€Ό CVE-2021-28692 β€Ό

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.

πŸ“– Read

via "National Vulnerability Database".
09:29
β€Ό CVE-2021-34385 β€Ό

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calculation of a length could lead to a heap overflow.

πŸ“– Read

via "National Vulnerability Database".
09:29
β€Ό CVE-2021-34373 β€Ό

Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could cause heap overflows, which might lead to information disclosure and denial of service.

πŸ“– Read

via "National Vulnerability Database".
?
09:58
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Feds Told to Better Manage Facial Recognition, Amid Privacy Concerns ❌

A GAO report finds government agencies are using the technology regularly in criminal investigations and to identify travelers, but need stricter management to protect people’s privacy and avoid inaccurate identification

πŸ“– Read

via "Threat Post".
?
11:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ 9 Hot Trends in Cybersecurity Mergers & Acquisitions πŸ•΄

Security experts share their observations of the past year in cybersecurity M&A, highlighting key trends and notable deals.

πŸ“– Read

via "Dark Reading".
11:25
🦿 Ransomware experts urge victims not to pay, but are they listening? 🦿

The number of attacks from, and payouts to, ransomware extortionists continue to rise despite only 20% saying giving into demands is the best course, Menlo Security finds.

πŸ“– Read

via "Tech Republic".
11:30
β€Ό CVE-2021-27902 β€Ό

An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.

πŸ“– Read

via "National Vulnerability Database".
11:30
β€Ό CVE-2021-27903 β€Ό

An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).

πŸ“– Read

via "National Vulnerability Database".
?
11:47
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ Colombian police arrest Gozi malware suspect after 8 years at large ⚠

Safe at home, apparently, but not so safe overseas.

πŸ“– Read

via "Naked Security".
?
13:10
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ›  Global Socket 1.4.32 πŸ› 

Global Socket is a tool for moving data from here to there, securely, fast, and through NAT and firewalls. It uses the Global Socket Relay Network to connect TCP pipes, has end-to-end encryption (using OpenSSL's SRP / RFC-5054), AES-256 and key exchange using 4096-bit Prime, requires no PKI, has Perfect Forward Secrecy, and TOR support.

πŸ“– Read

via "Packet Storm Security".
13:10
πŸ›  Faraday 3.16.0 πŸ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

πŸ“– Read

via "Packet Storm Security".
?
13:28
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Zero-Day Used to Wipe My Book Live Devices ❌

Threat actors may have been duking it out for control of the compromised devices, first using a 2018 RCE, then password-protecting a new vulnerability.

πŸ“– Read

via "Threat Post".
13:31
β€Ό CVE-2021-22376 β€Ό

There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality, availability and integrity.

πŸ“– Read

via "National Vulnerability Database".
13:31
β€Ό CVE-2021-35971 β€Ό

Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.

πŸ“– Read

via "National Vulnerability Database".
13:31
β€Ό CVE-2021-35973 β€Ό

NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This directly allows the attacker to change the web UI password, and eventually to enable debug mode (telnetd) and gain a shell on the device as the admin limited-user account (however, escalation to root is simple because of weak permissions on the /etc/ directory).

πŸ“– Read

via "National Vulnerability Database".
?
13:58
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Why MTTR is Bad for SecOps ❌

Kerry Matre, senior director at Mandiant, discusses the appropriate metrics to use to measure SOC and analyst performance, and how MTTR leads to bad behavior.

πŸ“– Read

via "Threat Post".
14:11
πŸ•΄ 7 Skills the Transportation Sector Needs to Fuel Its Security Teams πŸ•΄

Without a top-notch team to stop attackers, our favorite modes of transportation could come to a screeching halt.

πŸ“– Read

via "Dark Reading".
?
15:25
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Cyber investments are growing, but not enough 🦿

64% of respondents to PwC's latest CEO survey expect a jump in reportable ransomware and software supply chain incidents this year, and only 55% are prepared to respond.

πŸ“– Read

via "Tech Republic".
15:30
β€Ό CVE-2021-21675 β€Ό

A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests.

πŸ“– Read

via "National Vulnerability Database".
15:30
β€Ό CVE-2021-21672 β€Ό

Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

πŸ“– Read

via "National Vulnerability Database".
15:30
β€Ό CVE-2021-21671 β€Ό

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

πŸ“– Read

via "National Vulnerability Database".
?
16:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Intl. Law Enforcement Operation Takes Down DoubleVPN πŸ•΄

The VPN service allegedly provided a means for cybercriminals to target their victims, Europol officials report.

πŸ“– Read

via "Dark Reading".
16:23
πŸ” An Interview with Ben McGraw, Cybersecurity Manager at Digital Guardian Part II πŸ”

In part two of our Q&A with Ben McGraw, we discuss how automation will change the industry, how to improve the cybersecurity skills gap, and who is Digital Guardian's best basketball player.

πŸ“– Read

via "".
?
17:28
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Indexsinas SMB Worm Campaign Infests Whole Enterprises ❌

The self-propagating malware's attack chain is complex, using former NSA cyberweapons, and ultimately drops cryptominers on targeted machines.

πŸ“– Read

via "Threat Post".
17:31
β€Ό CVE-2021-22367 β€Ό

There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may lead to authentication bypass.

πŸ“– Read

via "National Vulnerability Database".
17:31
β€Ό CVE-2021-22353 β€Ό

There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the kernel to restart.

πŸ“– Read

via "National Vulnerability Database".
17:41
πŸ•΄ Impersonation Becomes Top Phishing Technique πŸ•΄

A new report finds IT, healthcare, and manufacturing are the industries most targeted by phishing emails.

πŸ“– Read

via "Dark Reading".
17:41
πŸ•΄ Attackers Already Unleashing Malware for Apple macOS M1 Chip πŸ•΄

Apple security expert Patrick Wardle found that some macOS malware written for the new M1 processor can bypass anti-malware tools.

πŸ“– Read

via "Dark Reading".
?
18:41
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ SMB Worm Targeting EternalBlue Vuln Spreads to US πŸ•΄

"Indexsinas" is the latest threat designed to exploit Windows servers that remain vulnerable to an NSA-developed exploit Microsoft patched more than four years ago.

πŸ“– Read

via "Dark Reading".
18:47
⚠ PrintNightmare, the zero-day hole in Windows – here’s what to do ⚠

All bugs are equal. But some bugs ar emore equal than others.

πŸ“– Read

via "Naked Security".
?
19:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-22346 β€Ό

There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may lead to the disclosure of user habits.

πŸ“– Read

via "National Vulnerability Database".
19:30
β€Ό CVE-2021-22350 β€Ό

There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the device to crash and restart.

πŸ“– Read

via "National Vulnerability Database".
19:41
πŸ•΄ SentinelOne Starts Trading on NYSE, Raises $1.2B in IPO πŸ•΄

IPO is the highest valued in cybersecurity history, according to reports.

πŸ“– Read

via "Dark Reading".
?
21:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-22345 β€Ό

There is an Input Verification Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds memory write.

πŸ“– Read

via "National Vulnerability Database".
1 July 2021
?
02:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-28803 β€Ό

This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.

πŸ“– Read

via "National Vulnerability Database".
02:30
β€Ό CVE-2018-25018 β€Ό

UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.

πŸ“– Read

via "National Vulnerability Database".
?
07:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-20752 β€Ό

Cross-site scripting vulnerability in IkaIka RSS Reader all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
?
08:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ LinkedIn’s 1.2B Data-Scrape Victims Already Being Targeted by Attackers ❌

A refined database of 88K U.S. business owners on LinkedIn has been posted in a hacker forum.

πŸ“– Read

via "Threat Post".
08:59
❌ Dropbox Used to Mask Malware Movement in Cyberespionage Campaign ❌

The ongoing spear-phishing campaign targeting the Afghan government uses Dropbox as an API that leaves no traces of communications with weirdo websites.

πŸ“– Read

via "Threat Post".
?
09:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-22347 β€Ό

There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.

πŸ“– Read

via "National Vulnerability Database".
?
10:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ S3 Ep39: Paying the date, #SocialMediaDay tips, and a special splintersode [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
?
11:12
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ S3 Ep39: Paying the date, #SocialMediaDay tips, and a special splintersode [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
11:12
❌ Data Exfiltration: What You Should Know to Prevent It ❌

Data leaks are a serious concern for companies of all sizes; if one occurs, it may put them out of business permanently. Here's how you can protect your organization from data theft.

πŸ“– Read

via "Threat Post".
11:12
πŸ•΄ Stop Playing Catchup: Move From Reactive to Proactive to Defeat Cyber Threats πŸ•΄

One-time reactive measures can't keep up. It's time to be proactive and pick our swords and not just our shields.

πŸ“– Read

via "Dark Reading".
?
11:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Babuk Ransomware Builder Mysteriously Appears in VirusTotal ❌

The gang's source code is now available to rivals and security researchers alike - and a decryptor likely is not far behind.

πŸ“– Read

via "Threat Post".
11:32
β€Ό CVE-2021-27477 β€Ό

When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a receive buffer for FL-net are overwritten. As a result, the PLC CPU detects a system error, and the affected products stop.

πŸ“– Read

via "National Vulnerability Database".
11:32
β€Ό CVE-2021-31813 β€Ό

Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.

πŸ“– Read

via "National Vulnerability Database".
11:32
β€Ό CVE-2021-22344 β€Ό

There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.

πŸ“– Read

via "National Vulnerability Database".
?
13:25
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How to set Google Search History to auto-delete on Android 🦿

If you don't like the idea of your Android search history being saved, Jack Wallen wants to show you how to set it to auto-delete.

πŸ“– Read

via "Tech Republic".
13:25
🦿 The possible reasons Google is moving away from APKs on Android 🦿

Google has announced it is moving away from the APK format for Android apps. Jack Wallen offers his opinion on why this could be happening.

πŸ“– Read

via "Tech Republic".
13:29
❌ Hacked Data for 69K LimeVPN Users Up for Sale on Dark Web ❌

LimeVPN has confirmed a data incident, and meanwhile its website has been knocked offline.

πŸ“– Read

via "Threat Post".
13:32
β€Ό CVE-2021-28423 β€Ό

Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-28424 β€Ό

A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.

πŸ“– Read

via "National Vulnerability Database".
13:32
β€Ό CVE-2021-28127 β€Ό

An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.

πŸ“– Read

via "National Vulnerability Database".
?
14:11
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ›  Falco 0.29.1 πŸ› 

Sysdig Falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Read

via "Packet Storm Security".
14:14
πŸ•΄ Why Are There Never Enough Logs During An Incident Response? πŸ•΄

Most security pros believe their responses could be dramatically quicker were the right logs available, and usually they're not.

πŸ“– Read

via "Dark Reading".
14:24
πŸ” CISA Shares New Ransomware Self-Assessment Tool πŸ”

The new security audit self-assessment tool is designed to help organizations better understand how well they're equipped to defend and recover from ransomware.

πŸ“– Read

via "".
?
14:42
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ NSA & CISA Issue Warning About Russian GRU Brute-Force Cyberattacks Against US, Global Orgs πŸ•΄

Fancy Bear nation-state hacking team add a modern twist on old-school hacking method by using a cluster of Kubernetes software containers to expedite credential theft.

πŸ“– Read

via "Dark Reading".
?
15:12
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Name That Edge Toon: Security Grill πŸ•΄

Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
15:25
🦿 Awareness of cyberattacks and cybersecurity may be lacking among workers 🦿

A survey of business professionals by Armis points to a lack of knowledge about recent incidents and proper cyber hygiene.

πŸ“– Read

via "Tech Republic".
15:31
β€Ό CVE-2020-27362 β€Ό

An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configuration file editor and escalate privileges.

πŸ“– Read

via "National Vulnerability Database".
15:31
β€Ό CVE-2020-4935 β€Ό

IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191753.

πŸ“– Read

via "National Vulnerability Database".
15:42
πŸ•΄ WhiteHat Security Rebrands as NTT Application Security πŸ•΄

The name change follows NTT Security Corporation's acquisition of WhiteHat in 2019.

πŸ“– Read

via "Dark Reading".
?
16:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Defeating Ransomware-as-a-Service? Think Intel-Sharing ❌

Aamir Lakhani, cybersecurity researcher and practitioner at FortiGuard Labs, explains the rise of RaaS and the critical role of threat intel in effectively defending against it.

πŸ“– Read

via "Threat Post".
?
17:31
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32731 β€Ό

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their username. The problem has been patched on XWiki 13.2RC1. As a workaround, it is possible to manually modify the `resetpasswordinline.vm` to perform the changes made to mitigate the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
?
17:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Linux Variant of REvil Ransomware Targets VMware’s ESXi, NAS Devices ❌

Criminals behind the potent REvil ransomware have ported the malware to Linux for targeted attacks.

πŸ“– Read

via "Threat Post".
?
19:12
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ CISA Urges Orgs to Disable Windows Print Spooler on Critical Systems πŸ•΄

Patches Microsoft issued last month not effective against exploits targeting "PrintNightmare" flaw, agency and others say.

πŸ“– Read

via "Dark Reading".
?
19:31
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-23209 β€Ό

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.

πŸ“– Read

via "National Vulnerability Database".
19:31
β€Ό CVE-2020-23205 β€Ό

A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted a payload entered into the "Site Name" field under the "Site Settings" module.

πŸ“– Read

via "National Vulnerability Database".
19:42
πŸ•΄ GitHub Unveils AI Tool to Speed Development, but Beware Insecure Code πŸ•΄

The company has created an AI system, dubbed Copilot, to offer code suggestions to developers, but warns that any code produced should be tested for defects and vulnerabilities.

πŸ“– Read

via "Dark Reading".
2 July 2021
?
07:31
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-26920 β€Ό

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid directly, since Druid also provides the Local InputSource, which allows the same level of access. But it is problematic when users interact with Druid indirectly through an application that allows users to specify the HTTP InputSource, but not the Local InputSource. In this case, users could bypass the application-level restriction by passing a file URL to the HTTP InputSource.

πŸ“– Read

via "National Vulnerability Database".
?
09:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ CISA Offers New Mitigation for PrintNightmare Bug ❌

CERT urges administrators to disable the Windows Print spooler service in Domain Controllers and systems that don’t print, while Microsoft attempts to clarify RCE flaw with a new CVE assignment.

πŸ“– Read

via "Threat Post".
09:32
β€Ό CVE-2021-27455 β€Ό

Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.

πŸ“– Read

via "National Vulnerability Database".
09:32
β€Ό CVE-2021-35029 β€Ό

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.

πŸ“– Read

via "National Vulnerability Database".
?
10:47
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ US email hacker gets his β€œcomputer trespass” conviction reversed ⚠

Court says that we need to "avoid a construction that makes some language mere surplusage."

πŸ“– Read

via "Naked Security".
10:56
🦿 Container security: How to get the most out of best practices 🦿

Containers are complex virtual entities that provide proven benefits to the business but also require strong security guidelines. Learn how to get the most out of container security best practices.

πŸ“– Read

via "Tech Republic".
?
11:13
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ WFH: A Smart Time to Revisit Employee Use of Social Media πŸ•΄

Employers have their hands full when it comes to monitoring online activities that could hurt the brand or violate the organization's core values.

πŸ“– Read

via "Dark Reading".
11:17
πŸ” Friday Five 7/2 πŸ”

Ransomware venture capital, VPN shutdowns, and the latest from Fancy Bear - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "".
11:32
β€Ό CVE-2021-36130 β€Ό

An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data fields. The attack could easily propagate across many pages for many users.

πŸ“– Read

via "National Vulnerability Database".
11:32
β€Ό CVE-2021-36132 β€Ό

An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform.

πŸ“– Read

via "National Vulnerability Database".
11:32
β€Ό CVE-2021-3606 β€Ό

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

πŸ“– Read

via "National Vulnerability Database".
?
12:43
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ 5 Mistakes That Impact a Security Team's Success πŸ•΄

The way we work and treat each other go a long way in improving our organizations' security posture.

πŸ“– Read

via "Dark Reading".
?
13:30
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ TrickBot Spruces Up Its Banking Trojan Module ❌

After focusing almost exclusively on delivering ransomware for the past year, the code changes could indicate that TrickBot is getting back into the bank-fraud game.

πŸ“– Read

via "Threat Post".
13:33
β€Ό CVE-2021-27950 β€Ό

A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to execute arbitrary SQL commands via the id parameter to mesdocs.ajax.php in azurWebEngine/eShop. By default, the query is executed as DBA.

πŸ“– Read

via "National Vulnerability Database".
13:33
β€Ό CVE-2021-32735 β€Ό

Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attacks. Malicious authenticated Panel users can escalate their privileges if they get access to the Panel session of an admin user. Visitors without Panel access can use the attack vector if the site allows changing site data from a frontend form. Kirby 3.5.7 patches the vulnerability. As a partial workaround, site administrators can protect against attacks from visitors without Panel access by validating or sanitizing provided data from the frontend form.

πŸ“– Read

via "National Vulnerability Database".
13:42
πŸ›  Suricata IDPE 6.0.3 πŸ› 

Suricata is a network intrusion detection and prevention engine developed by the Open Information Security Foundation and its supporting vendors. The engine is multi-threaded and has native IPv6 support. It's capable of loading existing Snort rules and signatures and supports the Barnyard and Barnyard2 tools.

πŸ“– Read

via "Packet Storm Security".
13:45
πŸ•΄ SOC Investment Improves Detection and Response Times, Data Shows πŸ•΄

A survey of IT and security pros finds many are confident in their ability to detect security incidents in near-real time or within minutes.

πŸ“– Read

via "Dark Reading".
?
14:13
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Microsoft Issues New CVE for 'PrintNightmare' Flaw πŸ•΄

Company says remote code execution issue in all Windows versions is different from one in Windows Print Spooler that it had patched last month, though both affect same function.

πŸ“– Read

via "Dark Reading".
14:13
πŸ•΄ Secured-Core PCs May Mitigate Firmware Attacks, But Adoption Lags πŸ•΄

Microsoft maintains that exploitation of recent Dell vulnerabilities would be blocked on ultra-secure PCs - but most systems do not have the technology yet.

πŸ“– Read

via "Dark Reading".
?
15:32
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-23402 β€Ό

All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.

πŸ“– Read

via "National Vulnerability Database".
?
16:13
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Barracuda Agrees to Acquire Skout Cybersecurity πŸ•΄

The acquisition will bring Barracuda into the extended detection and response (XDR) market with a tool for managed service providers.

πŸ“– Read

via "Dark Reading".
?
17:32
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32737 β€Ό

Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41, it is possible for a logged in admin user to add a script injection (cross-site-scripting) in the collection title. The problem is patched in version 1.6.41. As a workaround, one may manually patch the affected JavaScript files in lieu of updating.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2020-23185 β€Ό

A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
17:32
β€Ό CVE-2020-23178 β€Ό

An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.

πŸ“– Read

via "National Vulnerability Database".
?
18:56
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 You don't have to be a tech expert to become a cybersecurity pro 🦿

Attention to detail, creativity and perseverance are key traits for a good white hat hacker. These positions are in high demand.

πŸ“– Read

via "Tech Republic".
?
21:32
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-36146 β€Ό

ACRN before 2.5 has a devicemodel/hw/pci/xhci.c NULL Pointer Dereference for a trb pointer.

πŸ“– Read

via "National Vulnerability Database".
21:32
β€Ό CVE-2021-34527 β€Ό

Windows Print Spooler Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
5 July 2021
?
09:02
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Ransomware Defense: Top 5 Things to Do Right Now ❌

Matt Bromiley, senior consultant with Mandiant Managed Defense, discusses the top tricks and tips for protecting enterprise environments from ransomware.

πŸ“– Read

via "Threat Post".
?
09:35
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-23401 β€Ό

This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False.

πŸ“– Read

via "National Vulnerability Database".
?
11:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Watch for Cybersecurity Games at the Tokyo Olympics πŸ•΄

The cybersecurity professionals guarding the Summer Olympics are facing at least as much competition as the athletes, and their failure could have steeper ramifications.

πŸ“– Read

via "Dark Reading".
11:18
⚠ Kaseya ransomware attackers say: β€œPay $70 million and we’ll set everyone free” ⚠

Are you feeling generous? Do you want to help others? These cybercriminals are hoping someone is and does...

πŸ“– Read

via "Naked Security".
?
13:35
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-26763 β€Ό

The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.

πŸ“– Read

via "National Vulnerability Database".
13:44
πŸ›  SQLMAP - Automatic SQL Injection Tool 1.5.7 πŸ› 

sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.

πŸ“– Read

via "Packet Storm Security".
?
16:49
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ Kaseya ransomware attackers say: β€œPay $70 million and we’ll set everyone free” ⚠

Are you feeling generous? Do you want to help others? These cybercriminals are hoping someone is and does...

πŸ“– Read

via "Naked Security".
16:49
⚠ S3 Ep 39.5: A conversation with Eva Galperin [Podcast] ⚠

Cryptography, privacy, stalkerware and how infosec professionals relax. Listen, enjoy and learn!

πŸ“– Read

via "Naked Security".
?
17:32
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Kaseya Attack Fallout: CISA, FBI Offer Guidance ❌

Following a brazen ransomware attack by the REvil cybergang, CISA and FBI offer guidance to victims.

πŸ“– Read

via "Threat Post".
?
21:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-36158 β€Ό

In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.

πŸ“– Read

via "National Vulnerability Database".
6 July 2021
?
02:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32233 β€Ό

SmarterTools SmarterMail before Build 7776 allows XSS.

πŸ“– Read

via "National Vulnerability Database".
?
09:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-24389 β€Ό

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
09:36
β€Ό CVE-2021-24386 β€Ό

The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege users such as author+ to upload a malicious SVG and then perform XSS attacks by inducing another user to access the file directly. In v3.4, the plugin restricted such upload to editors and admin, with an option to also allow author to do so. The description of the plugin has also been updated with a security warning as upload of such content is intended.

πŸ“– Read

via "National Vulnerability Database".
09:36
β€Ό CVE-2021-24407 β€Ό

The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
?
10:58
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Critical flaws in Windows Print spooler service could allow for remote attacks 🦿

Administrators are urged to apply the latest patches from Microsoft and disable the Windows Print spooler service in domain controllers and systems not used for printing.

πŸ“– Read

via "Tech Republic".
?
11:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ 8 Ways to Preserve Legal Privilege After a Cybersecurity Incident πŸ•΄

Knowing your legal distinctions can make defense easier should you end up in court after a breach, attack, or data loss.

πŸ“– Read

via "Dark Reading".
?
11:36
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-27930 β€Ό

Multiple stored cross-site scripting (XSS) vulnerabilities in IRIS IrisNext 9.5.16 allow remote authenticated users to inject arbitrary web script or HTML via a document or folder name that is mishandled when rendering the contact form or search form.

πŸ“– Read

via "National Vulnerability Database".
11:36
β€Ό CVE-2021-32559 β€Ό

An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.

πŸ“– Read

via "National Vulnerability Database".
?
12:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Cyberattack on Kaseya Nets More Than 1,000 Victims, $70M Ransom Demand πŸ•΄

The provider of remote monitoring and management services warns customers to not run its software until a patch is available and manually installed.

πŸ“– Read

via "Dark Reading".
?
12:58
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Kaseya supply chain attack impacts more than 1,000 companies 🦿

The REvil group is claiming that over 1 million devices have been infected and is demanding $70 million for a universal decryption key.

πŸ“– Read

via "Tech Republic".
13:02
❌ Kaseya Patches Imminent After Zero-Day Exploits, 1,500 Impacted ❌

REvil ransomware gang lowers price for universal decryptor after massive worldwide ransomware push against Kaseya security vulnerability CVE-2021-30116.

πŸ“– Read

via "Threat Post".
?
13:28
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 The Audacity! How to wreck an open-source project and anger a community 🦿

Audacity software has been acquired, and the new verbiage added to the privacy policy has the open-source community up in arms.

πŸ“– Read

via "Tech Republic".
13:36
β€Ό CVE-2021-31771 β€Ό

Splinterware System Scheduler Professional version 5.30 is subject to insecure folders permissions issue impacting where the service 'WindowsScheduler' calls its executable. This allow a non-privileged user to execute arbitrary code with elevated privileges (system level privileges as "nt authority\system") since the service runs as Local System.

πŸ“– Read

via "National Vulnerability Database".
13:36
β€Ό CVE-2021-32740 β€Ό

Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a maliciously crafted template may result in uncontrolled resource consumption, leading to denial of service when matched against a URI. In typical usage, templates would not normally be read from untrusted user input, but nonetheless, no previous security advisory for Addressable has cautioned against doing this. Users of the parsing capabilities in Addressable but not the URI template capabilities are unaffected. The vulnerability is patched in version 2.8.0. As a workaround, only create Template objects from trusted sources that have been validated not to produce catastrophic backtracking.

πŸ“– Read

via "National Vulnerability Database".
?
14:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ It's High Time for a Security Scoring System for Applications and Open Source Libraries πŸ•΄

A benchmarking system would help buyers choose more secure software products and, more importantly, light a fire underneath software producers to make products secure.

πŸ“– Read

via "Dark Reading".
14:20
πŸ” What is GLBA Compliance? Understanding the Data Protection Requirements of the Gramm-Leach-Bliley Act in 2021 πŸ”

Learn about what GLBA means for data protection and how to achieve GLBA compliance in Data Protection 101, our series on the fundamentals of information security.

πŸ“– Read

via "".
14:33
❌ Western Digital Users Face Another RCE ❌

Say hello to one more zero-day and yet more potential remote data death for those who can’t/won’t upgrade their My Cloud storage devices.

πŸ“– Read

via "Threat Post".
?
14:58
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 1 in 4 employees say they still have access to accounts from past jobs, survey finds 🦿

Nearly half of professionals also admit to sharing passwords and more than a third say they write them on paper, according to Beyond Identity.

πŸ“– Read

via "Tech Republic".
?
16:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Workers Careless in Sharing & Reusing Corporate Secrets πŸ•΄

A new survey shows leaked enterprise secrets costs companies millions of dollars each year.

πŸ“– Read

via "Dark Reading".
16:28
🦿 The mobile and desktop versions of Firefox Total Cookie Protection are now available 🦿

Jack Wallen explains how to protect your web browsing from supercookies with Firefox's new privacy feature.

πŸ“– Read

via "Tech Republic".
?
17:03
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Android Apps in Google Play Harvest Facebook Credentials ❌

The apps all used an unusual tactic of loading a legitimate Facebook page as part of the data theft.

πŸ“– Read

via "Threat Post".
?
17:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-34190 β€Ό

A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Name" or "Prefix" fields under the "Create New Rate" module.

πŸ“– Read

via "National Vulnerability Database".
?
19:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Researchers Learn From Nation-State Attackers' OpSec Mistakes πŸ•΄

Security researchers discuss how a series of simple and consistent mistakes helped them learn more about ITG18, better known as Charming Kitten.

πŸ“– Read

via "Dark Reading".
?
19:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-22249 β€Ό

Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2021-22229 β€Ό

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2020-22251 β€Ό

Cross Site Scripting (XSS) vulnerability in phpList 3.5.3 via the login name field in Manage Administrators when adding a new admin.

πŸ“– Read

via "National Vulnerability Database".
19:37
β€Ό CVE-2020-23697 β€Ό

Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.

πŸ“– Read

via "National Vulnerability Database".
?
21:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-22228 β€Ό

An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql.

πŸ“– Read

via "National Vulnerability Database".
7 July 2021
?
00:33
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Pro-Trump β€˜Gettr’ Social Platform Hacked On Day One ❌

The newborn platform was inundated by Sonic the Hedgehog-themed porn and had prominent users' profiles defaced. Next, hackers posted its user database online.

πŸ“– Read

via "Threat Post".
?
02:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-35039 β€Ό

kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument.

πŸ“– Read

via "National Vulnerability Database".
?
07:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-20738 β€Ό

WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain sensitive information via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
07:37
β€Ό CVE-2021-20776 β€Ό

Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary command via telnet.

πŸ“– Read

via "National Vulnerability Database".
?
08:03
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Microsoft Releases Emergency Patch for PrintNightmare Bugs ❌

The fix doesn’t cover the entire problem nor all affected systems however, so the company also is offering workarounds and plans to release further remedies at a later date.

πŸ“– Read

via "Threat Post".
?
09:03
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Cloud Cryptomining Swindle in Google Play Rakes in Cash ❌

At least 25 apps have lured in tens of thousands of victims with the promise of helping them cash in on the cryptomining craze.

πŸ“– Read

via "Threat Post".
?
09:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-22227 β€Ό

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

πŸ“– Read

via "National Vulnerability Database".
09:37
β€Ό CVE-2021-22230 β€Ό

Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.

πŸ“– Read

via "National Vulnerability Database".
09:49
⚠ PrintNightmare official patch is out – update now! ⚠

Patch now! This security hole could allow almost anyone to take over your whole network from almost any account on almost any computer.

πŸ“– Read

via "Naked Security".
?
11:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Autonomous Security Is Essential if the Edge Is to Scale Properly πŸ•΄

Service demands at the network edge mean customers need to get cost, performance, and security right.

πŸ“– Read

via "Dark Reading".
11:28
🦿 Microsoft rolls out emergency patch for critical PrintNightmare flaw 🦿

Fixing a serious security hole in the Windows Print spooler service, the patch is available for almost all versions of Windows, even Windows 7.

πŸ“– Read

via "Tech Republic".
11:33
❌ Why I Love (Breaking Into) Your Security Appliances ❌

David "moose" Wolpoff, CTO at Randori, discusses security appliances and VPNs and how attackers only have to "pick one lock" to invade an enterprise through them.

πŸ“– Read

via "Threat Post".
11:37
β€Ό CVE-2021-34623 β€Ό

A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

πŸ“– Read

via "National Vulnerability Database".
11:37
β€Ό CVE-2021-34624 β€Ό

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

πŸ“– Read

via "National Vulnerability Database".
11:37
β€Ό CVE-2021-22555 β€Ό

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

πŸ“– Read

via "National Vulnerability Database".
11:37
β€Ό CVE-2021-36212 β€Ό

app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.

πŸ“– Read

via "National Vulnerability Database".
?
12:03
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Fake Kaseya VSA Security Update Drops Cobalt Strike ❌

Threat actors are planting Cobalt Strike backdoors by malspamming a bogus Microsoft update along with a SecurityUpdates.exe.

πŸ“– Read

via "Threat Post".
12:17
πŸ•΄ Security 101: The 'PrintNightmare' Flaw πŸ•΄

A closer look at the printer software vulnerability - and what you can do about it.

πŸ“– Read

via "Dark Reading".
12:28
🦿 Critical flaws in Windows Print spooler service could allow for remote attacks 🦿

Administrators are urged to apply the latest patches from Microsoft and disable the Windows Print spooler service in domain controllers and systems not used for printing.

πŸ“– Read

via "Tech Republic".
?
12:58
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Critical flaws in Windows Print spooler service could allow for remote attacks 🦿

Administrators are urged to apply the latest patches from Microsoft and disable the Windows Print spooler service in domain controllers and systems not used for printing.

πŸ“– Read

via "Tech Republic".
?
13:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ›  Zeek 4.0.3 πŸ› 

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. While focusing on network security monitoring, Zeek provides a comprehensive platform for more general network traffic analysis as well. Well grounded in more than 15 years of research, Zeek has successfully bridged the traditional gap between academia and operations since its inception. Today, it is relied upon operationally in particular by many scientific environments for securing their cyber-infrastructure. Zeek's user community includes major universities, research labs, supercomputing centers, and open-science communities. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
?
13:33
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Suspected β€˜Dr HeX’ Hacker Busted for 9 Years of Phishing ❌

The unnamed suspect allegedly helped to develop carding and phishing kits with the aim of stealing customers' bank-card data.

πŸ“– Read

via "Threat Post".
13:37
β€Ό CVE-2020-24143 β€Ό

Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2020-20211 β€Ό

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2021-32535 β€Ό

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administratorÒ€ℒs permission and execute arbitrary functions.

πŸ“– Read

via "National Vulnerability Database".
13:37
β€Ό CVE-2021-32514 β€Ό

Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device.

πŸ“– Read

via "National Vulnerability Database".
13:47
πŸ•΄ Microsoft Releases Emergency Patch for 'PrintNightmare' Flaw πŸ•΄

Urges Organizations to immediately apply security update citing exploit activity.

πŸ“– Read

via "Dark Reading".
?
14:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Are Security Attestations a Necessity for SaaS Businesses? πŸ•΄

Are security attestations becoming business imperatives, or are they merely token additions on the list of regulatory requirements?

πŸ“– Read

via "Dark Reading".
14:28
🦿 Bitwarden has a new Send feature: Here's how to use it 🦿

This tool will make this productβ€”probably the best password manager on the marketβ€”even better.

πŸ“– Read

via "Tech Republic".
?
15:03
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ MacOS Targeted in WildPressure APT Malware Campaign ❌

Threat actors enlist compromised WordPress websites in campaign targeting macOS users.

πŸ“– Read

via "Threat Post".
?
15:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-20416 β€Ό

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 196218.

πŸ“– Read

via "National Vulnerability Database".
15:37
β€Ό CVE-2021-20415 β€Ό

IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.

πŸ“– Read

via "National Vulnerability Database".
?
15:58
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 What to do when 2FA won't allow you into your Linux servers 🦿

If two-factor authentication logins on your Linux servers are giving you fits, Jack Wallen has the solution for you.

πŸ“– Read

via "Tech Republic".
16:03
❌ Critical Sage X3 RCE Bug Allows Full System Takeovers ❌

Security vulnerabilities in the ERP platform could allow attackers to tamper with or sabotage victims' business-critical processes and to intercept data.

πŸ“– Read

via "Threat Post".
16:17
πŸ•΄ Sophos Acquires Capsule8 for Linux Server & Container Security πŸ•΄

The deal was announced the same day ZeroFox bought Dark Web intelligence firm Vigilante as a wave of security M&A continues.

πŸ“– Read

via "Dark Reading".
16:20
πŸ” Changes to Nevada's Privacy Law Includes Requirements for Data Brokers πŸ”

Recent changes to Nevada’s privacy law, effective October 1, 2021, give residents a broader right to opt out of sales and puts the onus on "data brokers" to respond to such requests.

πŸ“– Read

via "".
?
16:47
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Fake Android Apps Promise Cryptomining Services to Steal Funds πŸ•΄

Researchers discover more than 170 Android apps that advertise cloud cryptocurrency mining services and fail to deliver.

πŸ“– Read

via "Dark Reading".
?
17:28
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 $13.7 million: Atlas VPN adds up the impact of the top 10 most successful blockchain scams 🦿

A new report finds that fake investment scams have netted the most funds among all the types of active blockchain scams.

πŸ“– Read

via "Tech Republic".
17:37
β€Ό CVE-2020-23702 β€Ό

Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php.

πŸ“– Read

via "National Vulnerability Database".
17:37
β€Ό CVE-2021-36217 β€Ό

Avahi 0.8 allows a local denial of service (NULL pointer dereference and daemon crash) against avahi-daemon via the D-Bus interface or a "ping .local" command.

πŸ“– Read

via "National Vulnerability Database".
?
18:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours πŸ•΄

Automation allowed a REvil affiliate to move from exploitation of vulnerable servers to installing ransomware on downstream companies faster than most defenders could react.

πŸ“– Read

via "Dark Reading".
18:28
🦿 Scammers exploiting Kaseya ransomware attack to deploy malware 🦿

A new phishing campaign claims to offer a security update for Kaseya's VSA software but actually tries to install malware, says Malwarebytes.

πŸ“– Read

via "Tech Republic".
?
19:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32714 β€Ό

hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in "request smuggling" or "desync attacks." The vulnerability is patched in version 0.14.10. Two possible workarounds exist. One may reject requests manually that contain a `Transfer-Encoding` header or ensure any upstream proxy rejects `Transfer-Encoding` chunk sizes greater than what fits in 64-bit unsigned integers.

πŸ“– Read

via "National Vulnerability Database".
19:38
β€Ό CVE-2007-5002 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
?
21:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-21775 β€Ό

A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage.

πŸ“– Read

via "National Vulnerability Database".
21:38
β€Ό CVE-2021-21807 β€Ό

An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
8 July 2021
?
02:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-34430 β€Ό

Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.

πŸ“– Read

via "National Vulnerability Database".
?
07:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-28809 β€Ό

An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later

πŸ“– Read

via "National Vulnerability Database".
?
09:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-31817 β€Ό

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

πŸ“– Read

via "National Vulnerability Database".
09:38
β€Ό CVE-2021-31816 β€Ό

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

πŸ“– Read

via "National Vulnerability Database".
?
10:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Ransomware: Top 5 more things to know 🦿

Ransomware attacks are getting bigger and harder to defend against. Tom Merritt lists five more things about ransomware you need to know.

πŸ“– Read

via "Tech Republic".
?
11:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ What Colonial Pipeline Means for Commercial Building Cybersecurity πŸ•΄

Banks and hospitals may be common targets, but now commercial real estate must learn to protect itself against stealthy hackers.

πŸ“– Read

via "Dark Reading".
?
11:38
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-21779 β€Ό

A use-after-free vulnerability exists in the way WebkitÒ€ℒs GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
11:48
πŸ•΄ The NSA's 'New' Mission: Get More Public With the Private Sector πŸ•΄

The National Security Agency's gradual emergence from the shadows was "inevitable" in cybersecurity, says Vinnie Liu, co-founder and CEO of offensive security firm Bishop Fox and a former NSA analyst. Now the agency has to figure out how to best work with the private sector, especially organizations outside the well-resourced and seasoned Fortune 100.

πŸ“– Read

via "Dark Reading".
?
12:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Kaseya Hacked via Authentication Bypass πŸ•΄

The Kaseya ransomware attack is believed to have been down to an authentication bypass. Yes, ransomware needs to be on your radar -- but good authentication practices are also imperative.

πŸ“– Read

via "Dark Reading".
12:29
🦿 Android app users targeted with cryptomining scams 🦿

Found on Google Play and third-party app stores, the apps discovered by Lookout stole an estimated $350,000 from more than 93,000 people.

πŸ“– Read

via "Tech Republic".
12:29
🦿 77% of executives plan to hire in the months ahead, according to a new poll 🦿

West Monroe's executive poll details third-quarter hiring expectations, cybersecurity preparedness, investments to digitize business operations and more.

πŸ“– Read

via "Tech Republic".
?
12:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 "Black Widow" digital premier a cover for malware and scams, says Kaspersky 🦿

Phishing, malicious files and other forms of fraud have followed the highly awaited movie since it was first delayed due to COVID-19. On the eve of its actual release, the scams have begun anew.

πŸ“– Read

via "Tech Republic".
?
13:34
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ How Fake Accounts and Sneaker-Bots Took Over the Internet ❌

Jason Kent, hacker-in-residence at Cequence Security, discusses fake online accounts, and the fraud they carry out on a daily basis.

πŸ“– Read

via "Threat Post".
13:38
β€Ό CVE-2021-29150 β€Ό

A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-25440 β€Ό

Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an escalated privilege.

πŸ“– Read

via "National Vulnerability Database".
13:38
β€Ό CVE-2021-25439 β€Ό

Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.

πŸ“– Read

via "National Vulnerability Database".
13:50
⚠ PrintNightmare official patch is out – update now! ⚠

Patch now! This security hole could allow almost anyone to take over your whole network from almost any account on almost any computer.

πŸ“– Read

via "Naked Security".
?
15:29
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Microsoft patches remaining versions of Windows against PrintNightmare flaw 🦿

Patches to fix a severe flaw in the Windows Print spooler are now available for Windows 10 Version 1607, Windows Server 2012 and Windows Server 2016.

πŸ“– Read

via "Tech Republic".
15:34
❌ Coursera Flunks API Security Test in Researchers’ Exam ❌

The problem APIs included numero uno on the OWASP API Security Top 10: a Broken Object Level Authorization (BOLA) issue that could have exposed personal data.

πŸ“– Read

via "Threat Post".
15:38
β€Ό CVE-2021-29711 β€Ό

IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Force ID: 200965.

πŸ“– Read

via "National Vulnerability Database".
15:39
β€Ό CVE-2021-34609 β€Ό

A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
?
15:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How to define DNS in Docker containers 🦿

Jack Wallen shows you how to configure specific DNS servers for your Docker container deployments.

πŸ“– Read

via "Tech Republic".
?
17:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ New WildPressure Malware Capable of Targeting Windows and MacOS πŸ•΄

The Trojan sends information back to the attackers' servers about the programming language of a target device.

πŸ“– Read

via "Dark Reading".
?
17:34
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Oil & Gas Targeted in Year-Long Cyber-Espionage Campaign ❌

A global effort to steal information from energy companies is using sophisticated social engineering to deliver Agent Tesla and other RATs.

πŸ“– Read

via "Threat Post".
17:39
β€Ό CVE-2020-20363 β€Ό

Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.

πŸ“– Read

via "National Vulnerability Database".
17:39
β€Ό CVE-2021-1596 β€Ό

Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. These vulnerabilities are due to incorrect processing of certain LLDP packets at ingress time. An attacker could exploit these vulnerabilities by sending crafted LLDP packets to an affected device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, which could cause the device to crash and reload, resulting in a DoS condition. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

πŸ“– Read

via "National Vulnerability Database".
17:39
β€Ό CVE-2021-1603 β€Ό

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker would need valid administrative credentials.

πŸ“– Read

via "National Vulnerability Database".
17:51
πŸ” CEO, COO Indicted in Biotech IP Theft Case’s Latest Turn πŸ”

Two executives reportedly used stolen intellectual property to build their company up to a nearly $1 billion valuation, the DOJ announced this week.

πŸ“– Read

via "".
?
18:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Morgan Stanley Discloses Data Breach πŸ•΄

Attackers were able to compromise customers' personal data by targeting the Accellion FTA server of a third-party vendor.

πŸ“– Read

via "Dark Reading".
?
19:39
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-34613 β€Ό

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
9 July 2021
?
08:04
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Lazarus Targets Job-Seeking Engineers with Malicious Documents ❌

Notorious North Korean APT impersonates Airbus, General Motors and Rheinmetall to lure potential victims into downloading malware.

πŸ“– Read

via "Threat Post".
?
09:14
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-3570 β€Ό

A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw affects linuxptp versions before 3.1.1, before 2.0.1, before 1.9.3, before 1.8.1, before 1.7.1, before 1.6.1 and before 1.5.1.

πŸ“– Read

via "National Vulnerability Database".
?
10:21
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ” Friday Five 7/9 πŸ”

Ransomware negotiators, cyber risks to the financial system, and why traditional passwords are here to stay - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "".
?
10:49
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Cartoon Caption Winner: Sight Unseen πŸ•΄

And the winner of Dark Reading's June contest is ...

πŸ“– Read

via "Dark Reading".
?
11:14
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2012-5632 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
11:14
β€Ό CVE-2012-0832 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
?
11:49
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ It's in the Game (but It Shouldn't Be) πŸ•΄

Five ways that game developers (and others) can avoid falling victim to an attack like the one that hit EA.

πŸ“– Read

via "Dark Reading".
?
12:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Warning: 1 in 3 employees are likely to fall for a phishing scam 🦿

Cybersecurity training company KnowBe4 reports that the number of employees likely to fall for phishing emails drops dramatically with proper instruction on how to recognize an attack.

πŸ“– Read

via "Tech Republic".
?
13:14
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-27035 β€Ό

A maliciously crafted TIFF, PDF, PICT or DWF files in Autodesk 2018, 2017, 2013, 2012, 2011 can be forced to read beyond allocated boundaries when parsing the TIFF, PDF, PICT or DWF files. This vulnerability can be exploited to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
13:14
β€Ό CVE-2021-27036 β€Ό

A maliciously crafted PDF, PICT or TIFF file can be used to write beyond the allocated buffer while parsing PDF, PICT or TIFF files in Autodesk 2018, 2017, 2013, 2012, 2011. This vulnerability can be exploited to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
13:14
β€Ό CVE-2021-30117 β€Ό

SQL injection exists in Kaseya VSA before 9.5.6.

πŸ“– Read

via "National Vulnerability Database".
13:14
β€Ό CVE-2021-32752 β€Ό

Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server. The vulnerability has been fixed in version 3.0.4. As a workaround, one may disable the plugin if untrustworthy sources have admin access.

πŸ“– Read

via "National Vulnerability Database".
?
14:20
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ Where do all those cybercrime payments go? ⚠

Yes, the headline is a rhetorical question. But sometimes we get literal answers, and they're well worth remembering.

πŸ“– Read

via "Naked Security".
14:29
🦿 More sharing, less shame: CompTIA ISAO wants to change the standard response to ransomware attacks 🦿

The information sharing organization helps companies deal with security threats and supports more collaboration overall.

πŸ“– Read

via "Tech Republic".
14:35
❌ Cisco BPA, WSA Bugs Allow Remote Cyberattacks ❌

The high-severity security vulnerabilities allow elevation of privileges, leading to data theft and more.

πŸ“– Read

via "Threat Post".
?
14:59
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 How to prevent ransomware attacks with a zero-trust security model 🦿

Ransomware attacks are rampant, with thousands taking place every single day. Learn how a zero-trust security model can protect your organization.

πŸ“– Read

via "Tech Republic".
15:05
❌ Microsoft Office Users Warned on New Malware-Protection Bypass ❌

Word and Excel documents are enlisted to disable Office macro warnings, so the Zloader banking malware can be downloaded onto systems without security tools flagging it.

πŸ“– Read

via "Threat Post".
15:15
β€Ό CVE-2021-3541 β€Ό

A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.

πŸ“– Read

via "National Vulnerability Database".
?
16:19
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ CISA Analysis Reveals Successful Attack Techniques of FY 2020 πŸ•΄

The analysis shows potential attack paths and the most effective techniques for each tactic documented in CISA's Risk and Vulnerability Assessments.

πŸ“– Read

via "Dark Reading".
?
17:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-24007 β€Ό

Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
17:15
β€Ό CVE-2021-22129 β€Ό

Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
?
17:49
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ How Dangerous is Malware? New Report Finds It's Tough to Tell πŸ•΄

Determining which malware is most damaging, and worthy of immediate attention, has become difficult in environments filled with alerts and noise.

πŸ“– Read

via "Dark Reading".
?
19:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-36367 β€Ό

PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).

πŸ“– Read

via "National Vulnerability Database".
19:15
β€Ό CVE-2021-36371 β€Ό

Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certificate requirements (i.e., mTLS cert_required) on backend upstreams when more than one TLSContext is defined and at least one configuration exists that does not require client certificate authentication. The attacker must send an SNI specifying an unprotected backend and an HTTP Host header specifying a protected backend.

πŸ“– Read

via "National Vulnerability Database".
?
21:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2020-25394 β€Ό

A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Content" parameter.

πŸ“– Read

via "National Vulnerability Database".
21:15
β€Ό CVE-2020-25876 β€Ό

A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Page Title' parameter.

πŸ“– Read

via "National Vulnerability Database".
10 July 2021
?
10:05
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Cyber Polygon 2021: Towards Secure Development of Digital Ecosystems ❌

Cybersecurity is one of the most important topics on the global agenda, boosted by the pandemic. As the global digitalisation is further accelerating, the world is becoming ever more interconnected. Digital ecosystems are being created all around us: countries, corporations and individuals are taking advantage of the rapid spread of the Internet and smart devices. In this context, a single vulnerable link is enough to bring down the entire system, just like the domino effect.

πŸ“– Read

via "Threat Post".
?
13:15
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-29106 β€Ό

A reflected Cross Site Scripting (XXS) vulnerability in ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the userÒ€ℒs browser.

πŸ“– Read

via "National Vulnerability Database".
11 July 2021
?
02:16
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-29103 β€Ό

A reflected Cross Site Scripting (XXS) vulnerability in ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the userÒ€ℒs browser.

πŸ“– Read

via "National Vulnerability Database".
02:16
β€Ό CVE-2021-29105 β€Ό

A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.

πŸ“– Read

via "National Vulnerability Database".
12 July 2021
?
09:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-22917 β€Ό

Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing through Tor if adblocking was enabled.

πŸ“– Read

via "National Vulnerability Database".
09:17
β€Ό CVE-2021-27293 β€Ό

RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp will be stuck processing it for an exceedingly long time. Thus the remote server can trigger Denial of Service.

πŸ“– Read

via "National Vulnerability Database".
?
10:51
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Navigating Active Directory Security: Dangers and Defenses πŸ•΄

Microsoft Active Directory, ubiquitous across enterprises, has long been a primary target for attackers seeking network access and sensitive data.

πŸ“– Read

via "Dark Reading".
?
11:17
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-30129 β€Ό

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

πŸ“– Read

via "National Vulnerability Database".
11:17
β€Ό CVE-2021-32679 β€Ό

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized into a `DownloadResponse`, this could be used to trick users into downloading malicious files with a benign file extension. This would show in UI behaviours where Nextcloud applications would display a benign file extension (e.g. JPEG), but the file will actually be downloaded with an executable file extension. The vulnerability is patched in versions 19.0.13, 20.0.11, and 21.0.3. Administrators of Nextcloud instances do not have a workaround available, but developers of Nextcloud apps may manually escape the file name before passing it into `DownloadResponse`.

πŸ“– Read

via "National Vulnerability Database".
11:17
β€Ό CVE-2021-32678 β€Ό

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`) using the `@BruteForceProtection` annotation. Risk depends on the installed applications on the Nextcloud Server, but could range from bypassing authentication ratelimits or spamming other Nextcloud users. The vulnerability is patched in versions 19.0.13, 20.0.11, and 21.0.3. No workarounds aside from upgrading are known to exist.

πŸ“– Read

via "National Vulnerability Database".
11:20
πŸ•΄ AI and Cybersecurity: Making Sense of the Confusion πŸ•΄

Artificial intelligence is a maturing area in cybersecurity, but there are different concerns depending on whether you're a defender or an attacker.

πŸ“– Read

via "Dark Reading".
?
12:51
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Kaseya Releases Security Patch As Companies Continue to Recover πŸ•΄

Estimates indicate the number of affected companies could grow, while Kaseya faces renewed scrutiny as former employees reportedly criticize its lack of focus on security.

πŸ“– Read

via "Dark Reading".
?
13:07
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Kaseya Patches Zero-Days Used in REvil Attacks ❌

The security update addresses three VSA vulnerabilities used by the ransomware gang to launch a worldwide supply-chain attack on MSPs and their customers.

πŸ“– Read

via "Threat Post".
13:17
β€Ό CVE-2021-30639 β€Ό

A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests. This meant that once a non-blocking I/O error occurred, all future requests handled by that request object would fail. Users were able to trigger non-blocking I/O errors, e.g. by dropping a connection, thereby creating the possibility of triggering a DoS. Applications that do not use non-blocking I/O are not exposed to this vulnerability. This issue affects Apache Tomcat 10.0.3 to 10.0.4; 9.0.44; 8.5.64.

πŸ“– Read

via "National Vulnerability Database".
13:17
β€Ό CVE-2021-36382 β€Ό

Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).

πŸ“– Read

via "National Vulnerability Database".
13:17
β€Ό CVE-2020-18979 β€Ό

Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via theX-forwarded-for Header parameter.

πŸ“– Read

via "National Vulnerability Database".
?
13:51
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ Where do all those cybercrime payments go? ⚠

Yes, the headline is a rhetorical question. But sometimes we get literal answers, and they're well worth remembering.

πŸ“– Read

via "Naked Security".
14:01
🦿 The most dangerous messaging apps on Android 🦿

Messaging apps are becoming some of the most popular smartphone programs in the world, and that means more attempts to phish their users, Kaspersky finds.

πŸ“– Read

via "Tech Republic".
?
14:21
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
⚠ Don’t get tricked by this crashtastic iPhone Wi-Fi hack! ⚠

Learn how the trick works so that you can avoid it in case someone thinks it's a joke to catch you out.

πŸ“– Read

via "Naked Security".
?
15:07
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ Critical RCE Vulnerability in ForgeRock OpenAM Under Active Attack ❌

The attacks are enabled by an unpatched security vulnerability in ForgeRock's Access Management, a popular platform that front-ends web apps and remote-access setups.

πŸ“– Read

via "Threat Post".
15:18
β€Ό CVE-2021-32703 β€Ό

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
15:18
β€Ό CVE-2021-20414 β€Ό

IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216.

πŸ“– Read

via "National Vulnerability Database".
15:18
β€Ό CVE-2021-36381 β€Ό

In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_error= on the login screen of the Web application.

πŸ“– Read

via "National Vulnerability Database".
15:18
β€Ό CVE-2021-29803 β€Ό

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204164.

πŸ“– Read

via "National Vulnerability Database".
?
15:52
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ Microsoft Confirms Acquisition of RiskIQ πŸ•΄

RiskIQ's technology helps businesses assess their security across the Microsoft cloud, Amazon Web Services, other clouds, and on-premises.

πŸ“– Read

via "Dark Reading".
15:58
πŸ” European Authorities Bust Phishing Ring πŸ”

The group, which was based in Romania, reportedly conned online consumers out of $2 million.

πŸ“– Read

via "".
?
17:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32707 β€Ό

Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by default, render images in emails to not leak the read state. The privacy filter failed to filter images with a `background-image` CSS attribute. Note that the images were still passed through the Nextcloud image proxy, and thus there was no IP leakage. The issue was patched in version 1.9.6 and 1.10.0. No workarounds are known to exist.

πŸ“– Read

via "National Vulnerability Database".
?
17:37
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
❌ WordPress File Management Plugin Riddled with Critical Bugs ❌

The bugs allow a range of attacks on websites, including deleting blog pages and remote code execution.

πŸ“– Read

via "Threat Post".
?
18:22
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
πŸ•΄ SolarWinds Discloses Zero-Day Under Active Attack πŸ•΄

The company confirms this is a new vulnerability that is not related to the supply chain attack discovered in December 2020.

πŸ“– Read

via "Dark Reading".
?
19:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-24426 β€Ό

The Backup by 10Web ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Backup and Restore Plugin WordPress plugin through 1.0.20 does not sanitise or escape the tab parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
19:18
β€Ό CVE-2020-19907 β€Ό

A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.

πŸ“– Read

via "National Vulnerability Database".
19:18
β€Ό CVE-2021-24421 β€Ό

The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
?
21:18
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-32747 β€Ό

Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed to unauthorized users exists between versions 2.0.0 and 2.8.2. Custom variables are user-defined keys and values on configuration objects in Icinga 2. These are commonly used to reference secrets in other configurations such as check commands to be able to authenticate with a service being checked. Icinga Web 2 displays these custom variables to logged in users with access to said hosts or services. In order to protect the secrets from being visible to anyone, it's possible to setup protection rules and blacklists in a user's role. Protection rules result in `***` being shown instead of the original value, the key will remain. Backlists will hide a custom variable entirely from the user. Besides using the UI, custom variables can also be accessed differently by using an undocumented URL parameter. By adding a parameter to the affected routes, Icinga Web 2 will show these columns additionally in the respective list. This parameter is also respected when exporting to JSON or CSV. Protection rules and blacklists however have no effect in this case. Custom variables are shown as-is in the result. The issue has been fixed in the 2.9.0, 2.8.3, and 2.7.5 releases. As a workaround, one may set up a restriction to hide hosts and services with the custom variable in question.

πŸ“– Read

via "National Vulnerability Database".
21:18
β€Ό CVE-2021-32741 β€Ό

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
13 July 2021
?
02:06
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
🦿 Vulnerability in Schneider Electric PLCs allows for undetectable remote takeover 🦿

Dubbed Modipwn, the vulnerability affects a wide variety of Modicon programmable logic controllers used in manufacturing, utilities, automation and other roles.

πŸ“– Read

via "Tech Republic".
02:06
🦿 New phishing attack SpoofedScholars targets professors and writers specializing in the Middle East 🦿

Proofpoint security analysis details the latest attack that uses the lure of speaking at a conference to steal credentials.

πŸ“– Read

via "Tech Republic".
?
07:19
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-1899 β€Ό

Possible buffer over read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

πŸ“– Read

via "National Vulnerability Database".
07:19
β€Ό CVE-2021-35515 β€Ό

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

πŸ“– Read

via "National Vulnerability Database".
07:19
β€Ό CVE-2020-11307 β€Ό

Buffer overflow in modem due to improper array index check before copying into it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

πŸ“– Read

via "National Vulnerability Database".
?
09:19
πŸ›‘ Cybersecurity & Privacy news πŸ›‘
β€Ό CVE-2021-31892 β€Ό

A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 < 02.00.18), SINUMERIK Integrate Client 03 (All versions >= V03.00.12 < 03.00.18), SINUMERIK Integrate Client 04 (V04.00.02 and all versions >= V04.00.15 < 04.00.18), SINUMERIK Integrate for Production 4.1 (All versions < V4.1 SP10 HF3), SINUMERIK Integrate for Production 5.1 (V5.1), SINUMERIK Manage MyMachines (All versions), SINUMERIK Manage MyMachines /Remote (All versions), SINUMERIK Manage MyMachines /Spindel Monitor (All versions), SINUMERIK Manage MyPrograms (All versions), SINUMERIK Manage MyResources /Programs (All versions), SINUMERIK Manage MyResources /Tools (All versions), SINUMERIK Manage MyTools (All versions), SINUMERIK Operate V4.8 (All versions < V4.8 SP8), SINUMERIK Operate V4.93 (All versions < V4.93 HF7), SINUMERIK Operate V4.94 (All versions < V4.94 HF5), SINUMERIK Optimize MyProgramming /NX-Cam Editor (All versions). Due to an error in a third-party dependency the ssl flags used for setting up a TLS connection to a server are overwitten with wrong settings. This results in a missing validation of the server certificate and thus in a possible TLS MITM szenario.

πŸ“– Read

via "National Vulnerability Database".
09:19
β€Ό CVE-2021-34329 β€Ό

A vulnerability has been identified in JT2Go (All versions < V13.2), Solid Edge SE2021 (All Versions < SE2021MP5), Teamcenter Visualization (All versions < V13.2). The plmxmlAdapterSE70.dll library in affected applications lacks proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write past the fixed-length heap-based buffer. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13427)

πŸ“– Read

via "National Vulnerability Database".
09:19
β€Ό CVE-2021-34320 β€Ό

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affected applications lacks proper validation of user-supplied data when parsing JT files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13406)

πŸ“– Read

via "National Vulnerability Database".
09:19
β€Ό CVE-2021-31895 β€Ό

A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V4.3.7), RUGGEDCOM ROS M2200 (All versions < V4.3.7), RUGGEDCOM ROS M969 (All versions < V4.3.7), RUGGEDCOM ROS RMC (All versions < V4.3.7), RUGGEDCOM ROS RMC20 (All versions < V4.3.7), RUGGEDCOM ROS RMC30 (All versions < V4.3.7), RUGGEDCOM ROS RMC40 (All versions < V4.3.7), RUGGEDCOM ROS RMC41 (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RP110 (All versions < V4.3.7), RUGGEDCOM ROS RS400 (All versions < V4.3.7), RUGGEDCOM ROS RS401 (All versions < V4.3.7), RUGGEDCOM ROS RS416 (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V5.X (All versions < 5.5.4), RUGGEDCOM ROS RS8000 (All versions < V4.3.7), RUGGEDCOM ROS RS8000A (All versions < V4.3.7), RUGGEDCOM ROS RS8000H (All versions < V4.3.7), RUGGEDCOM ROS RS8000T (All versions < V4.3.7), RUGGEDCOM ROS RS900 (32M) V4.X (All versions < V4.3.7), RUGGEDCOM ROS RS900 (32M) V5.X (All versions < V5.5.4), RUGGEDCOM ROS RS900G (All versions < V4.3.7), RUGGEDCOM ROS RS900G (32M) V4.X (All versions < V4.3.7), RUGGEDCOM ROS RS900G (32M) V5.X (All versions < V5.5.4), RUGGEDCOM ROS RS900GP (All versions < V4.3.7), RUGGEDCOM ROS RS900L (All versions < V4.3.7), RUGGEDCOM ROS RS900W (All versions < V4.3.7), RUGGEDCOM ROS RS910 (All versions < V4.3.7), RUGGEDCOM ROS RS910L (All versions < V4.3.7), RUGGEDCOM ROS RS910W (All versions < V4.3.7), RUGGEDCOM ROS RS920L (All versions < V4.3.7), RUGGEDCOM ROS RS920W (All versions < V4.3.7), RUGGEDCOM ROS RS930L (All versions < V4.3.7), RUGGEDCOM ROS RS930W (All versions < V4.3.7), RUGGEDCOM ROS RS940G (All versions < V4.3.7), RUGGEDCOM ROS RS969 (All versions < V4.3.7), RUGGEDCOM ROS RSG2100 (32M) V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2100 (32M) V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2100 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2100P (All versions < V4.3.7), RUGGEDCOM ROS RSG2100P (32M) V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2100P (32M) V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2200 (All versions < V4.3.7), RUGGEDCOM ROS RSG2288 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2288 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2300 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2300 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2300P V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2300P V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2488 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2488 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG900 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG900 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG900C (All versions < V5.5.4), RUGGEDCOM ROS RSG900G V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG900G V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG900R (All versions < V5.5.4), RUGGEDCOM ROS RSG920P V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG920P V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSL910 (All versions < V5.5.4), RUGGEDCOM ROS RST2228 (All versions < V5.5.4), RUGGEDCOM ROS RST916C (All versions < V5.5.4), RUGGEDCOM ROS RST916P (All versions < V5.5.4), RUGGEDCOM ROS i800 (All versions < V4.3.7), RUGGEDCOM ROS i801 (All versions < V4.3.7), RUGGEDCOM ROS i802 (All versions < V4.3.7), RUGGEDCOM ROS i803 (All versions < V4.3.7). The DHCP client in affected devices fails to properly sanitize incoming DHCP packets. This could allow an unauthenticated remote attacker to cause memory to be overwritten, potentially allowing remote code execution.

πŸ“– Read

via "National Vulnerability Database".
09:19
β€Ό CVE-2021-34325 β€Ό

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affected applications lacks proper validation of user-supplied data when parsing JT files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13421)

πŸ“– Read

via "National Vulnerability Database".
09:19
β€Ό CVE-2021-34327 β€Ό

A vulnerability has been identified in JT2Go (All versions < V13.2), Solid Edge SE2021 (All Versions < SE2021MP5), Teamcenter Visualization (All versions < V13.2). The plmxmlAdapterSE70.dll library in affected applications lacks proper validation of user-supplied data when parsing ASM files. This could result in an out of bounds write past the fixed-length heap-based buffer. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13423)

πŸ“– Read

via "National Vulnerability Database".
09:19
β€Ό CVE-2021-34308 β€Ό

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13344)

πŸ“– Read

via "National Vulnerability Database".
09:25
β€Ό CVE-2021-34307 β€Ό

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13343)

πŸ“– Read

via "National Vulnerability Database".
09:25
β€Ό CVE-2021-33713 β€Ό

A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a hash function is called with an incorrect argument leading the application to crash. An attacker could leverage this vulnerability to cause a Denial-of-Service condition in the application.

πŸ“– Read

via "National Vulnerability Database".