πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-7126 β€Ό

A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7196 β€Ό

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7752 β€Ό

This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.

πŸ“– Read

via "National Vulnerability Database".
❌ β€˜Among Us’ Mobile Game Under Siege by Attackers ❌

Ongoing attacks on the wildly popular game Among Us are testing developers’ ability to keep up.

πŸ“– Read

via "Threat Post".
🦿 Enterprises confident Chief Sustainability Officer (CSO) will improve cybersecurity 🦿

98% of enterprises want CSOs, but 56% of industrial businesses don't have plans to introduce one to their company, according to a new Kaspersky report.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2017-18925 β€Ό

opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26566 β€Ό

A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a webu.c segmentation fault and kill the main process via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26161 β€Ό

In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Former Healthcare Exec Sentenced for Sabotaging COVID-19 Supply Deliveries πŸ”

The ex-VP conducted an intrusion into his former employer’s package shipping system and delayed PPE essential to healthcare workers.

πŸ“– Read

via "Digital Guardian".
πŸ•΄ Cybercriminals Extort Psychotherapy Patients Following Vastaamo Breach πŸ•΄

An attacker is running a Tor site to leak the session notes of 300 patients at Vastaamo, a Finnish psychotherapy facility.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-1915 β€Ό

An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft IE Browser Death March Hastens ❌

Internet Explorer redirects more traffic to Edge Chromium browser as Microsoft warns of the upcoming demise of the once dominant browser.

πŸ“– Read

via "Threat Post".
πŸ•΄ Neural Networks Help Users Pick More-Secure Passwords πŸ•΄

Typically, blocklists are used to prevent users from picking easily guessable patterns, but a small neural network can do the same job and suggests that complex password requirements are not necessary.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-27743 β€Ό

libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.

πŸ“– Read

via "National Vulnerability Database".
⚠ Phone scamming – friends don’t let friends get vished! ⚠

You probably back yourself not to be flattered or scared by a voice scammer - but what about vulnerable friends or relatives?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2018-21269 β€Ό

checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27180 β€Ό

konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7753 β€Ό

All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) [DNP] via trim().

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27182 β€Ό

Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, ixedit/editor_component.jsp, or the login form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27183 β€Ό

A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges of arbitrary user accounts, and have unspecified other impact.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-8956 β€Ό

Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.

πŸ“– Read

via "National Vulnerability Database".