■□□□□ CVE-2021-23888 - McAfee ePolicy Orchestrator HTML Injection
https://ricardojba.github.io/CVE-2021-23888-McAfee-ePolicy-Orchestrator-HTML-Injection/
https://ricardojba.github.io/CVE-2021-23888-McAfee-ePolicy-Orchestrator-HTML-Injection/
blog.vibri.us
CVE-2021-23888 McAfee ePolicy Orchestrator HTML Injection | vibrio's personal infosec blog
Product: McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 Type: OWASP Top Ten 2013 Category A10 - Unvalidated Redirects and Forwards Summary: Unvali...
■□□□□ A Windows hacker has found a never-before-seen Easter egg in the Windows 95 Internet Mail application, fifteen years after the software was released.
https://www.bleepingcomputer.com/news/microsoft/windows-95-easter-egg-discovered-after-being-hidden-for-15-years/
https://www.bleepingcomputer.com/news/microsoft/windows-95-easter-egg-discovered-after-being-hidden-for-15-years/
BleepingComputer
Windows 95 Easter egg discovered after being hidden for 25 years
A Windows hacker has found a never-before-seen Easter egg in the Windows 95 Internet Mail application, twnty-five years after the software was released.
■□□□□ #DataLeak: On March 9th, 2021, a database seemingly belonging to Guns.com was dumped on the popular dark web site ‘Raid Forums’.
https://www.ehackingnews.com/2021/03/threat-actor-targets-gunscom-spills.html
https://www.ehackingnews.com/2021/03/threat-actor-targets-gunscom-spills.html
cKure
■■■■■ #DataLeak: Researchers have discovered a new information-stealing trojan, which targets Android devices with an onslaught of data-exfiltration capabilities — from collecting browser searches to recording audio and phone calls. https://thehackernews…
■■■■■ Advanced Android Malware Posing as “System Update”.
https://blog.zimperium.com/new-advanced-android-malware-posing-as-system-update/
https://blog.zimperium.com/new-advanced-android-malware-posing-as-system-update/
■□□□□ Clop Ransomware group now contacts victims’ customers to force victims into pay a ransom.
■□□□□ US 🇺🇸 Gov Executive Order would oblige to disclose security breach impacting gov users
■■■■□ CallObfuscator - Obfuscate Specific Windows Apis With Different APIs.
https://github.com/d35ha/CallObfuscator
https://github.com/d35ha/CallObfuscator
GitHub
GitHub - d35ha/CallObfuscator: Obfuscate specific windows apis with different apis
Obfuscate specific windows apis with different apis - d35ha/CallObfuscator
■■■■□ Emba: analyzer for Linux-based firmware of embedded devices.
https://securityonline.info/emba-analyzer-for-linux-based-firmware-of-embedded-devices/
https://securityonline.info/emba-analyzer-for-linux-based-firmware-of-embedded-devices/
Daily CyberSecurity
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
■■■□□ New data suggests someone has compromised more than 21,000 Microsoft Exchange Server email systems worldwide and infected them with malware that invokes both KrebsOnSecurity and Yours Truly by name.
https://krebsonsecurity.com/2021/03/no-i-did-not-hack-your-ms-exchange-server/
https://krebsonsecurity.com/2021/03/no-i-did-not-hack-your-ms-exchange-server/
Krebs on Security
No, I Did Not Hack Your MS Exchange Server
New data suggests someone has compromised more than 21,000 Microsoft Exchange Server email systems worldwide and infected them with malware that invokes both KrebsOnSecurity and Yours Truly by name. Let's just get this out of the way right now: It…
■■■■■ CVE-2021-21123
https://youtu.be/Mr95IeGiTj0
https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2021-21123/
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html
https://youtu.be/Mr95IeGiTj0
https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2021-21123/
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html
YouTube
google chrome bug | CVE-2021-21123 PoC
Credit : @PuliczeK
Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski
#Bug is rewarded with $5000.
GitHub: https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
YouTube : https://www.youtube.com/channel/UCW3hDq…
Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski
#Bug is rewarded with $5000.
GitHub: https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
YouTube : https://www.youtube.com/channel/UCW3hDq…
■■■□□ #CyberAttack | Australia 🇦🇺
A cyber attack has hit the Australian Channel Nine’s live broadcasts causing the disruption of its operations. The broadcaster was unable to air its Sunday morning news program, which runs from 7:00 am to 1:00 pm from Sidney.
https://hackademicus.nl/hackers-disrupted-live-broadcasts-at-channel-nine-is-it-a-russian-retaliation/
A cyber attack has hit the Australian Channel Nine’s live broadcasts causing the disruption of its operations. The broadcaster was unable to air its Sunday morning news program, which runs from 7:00 am to 1:00 pm from Sidney.
https://hackademicus.nl/hackers-disrupted-live-broadcasts-at-channel-nine-is-it-a-russian-retaliation/
■■■■□ A critical flaw in the official Facebook for WordPress plugin could be abused exploited for remote code execution attacks.
https://securityaffairs.co/wordpress/116063/social-networks/facebook-wordpress-plugin-attacks.html
https://securityaffairs.co/wordpress/116063/social-networks/facebook-wordpress-plugin-attacks.html
Security Affairs
Experts found two flaws in Facebook for WordPress Plugin
A critical flaw in the official Facebook for WordPress plugin could be exploited by attackers for remote code execution attacks.
■■■■□ Intigriti — XSS Challenge 0321
XSS with CSRF Bypass
https://fh4ntke.medium.com/intigriti-xss-challenge-0321-472ae0a48254
XSS with CSRF Bypass
https://fh4ntke.medium.com/intigriti-xss-challenge-0321-472ae0a48254
Medium
Intigriti — XSS Challenge 0321
XSS with CSRF Bypass
■□□□□ ⚠️ Actor selling data allegedly of multiple organisations spread across Arabian peninsular / GCC incl. UAE 🇦🇪, KSA 🇸🇦, Qatar 🇶🇦, Kuwait 🇰🇼.
We requested for a sample and found the data to be inconsistent; in one instance the mail did not exist. Apparently another fraudster.
https://raidforums.com/Thread-SELLING-GCC-Countries-Big-Company-Base-UAE-Saudi-Arabia-Qatar-Kuveyt
We requested for a sample and found the data to be inconsistent; in one instance the mail did not exist. Apparently another fraudster.
https://raidforums.com/Thread-SELLING-GCC-Countries-Big-Company-Base-UAE-Saudi-Arabia-Qatar-Kuveyt
■■■■■ php hacked viz. a supply chain attack.
On 28th March, 2021 two malicious commits were pushed to the php-src repo from the names of Rasmus Lerdorf and myself. We don't yet know how exactly this happened, but everything points towards a compromise of the git.php.net server (rather than a compromise of an individual git account).
https://news-web.php.net/php.internals/113838
On 28th March, 2021 two malicious commits were pushed to the php-src repo from the names of Rasmus Lerdorf and myself. We don't yet know how exactly this happened, but everything points towards a compromise of the git.php.net server (rather than a compromise of an individual git account).
https://news-web.php.net/php.internals/113838