πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-25074 β€Ό

The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26818 β€Ό

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26822 β€Ό

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availability of the service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26821 β€Ό

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cloud Usage, Biometrics Surge As Remote Work Grows Permanent πŸ•΄

A new report reveals organizations are increasing their adoption of biometric authentication and disallowing SMS as a login method.

πŸ“– Read

via "Dark Reading".
πŸ” New Government Contractor Cybersecurity Requirements Loom πŸ”

A new cybersecurity rule will go into effect for DoD contractors at the end of the month to enhance the protection of unclassified information within the supply chain.

πŸ“– Read

via "Digital Guardian".
❌ Scalper-Bots Shake Down Desperate PS5, Xbox Series X Shoppers ❌

Retail bots are helping scalpers scoop up PS5, Xbox Series X inventory and charge massive markups.

πŸ“– Read

via "Threat Post".
❌ Colossal Intel Update Anchored by Critical Privilege-Escalation Bugs ❌

Intel released 40 security advisories in total, addressing critical- and high-severity flaws across its Active Management Technology, Wireless Bluetooth and NUC products.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-28368 β€Ό

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-7357 β€Ό

Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23968 β€Ό

Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27165 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-28050. Reason: This candidate is a reservation duplicate of CVE-2020-28050. Notes: All CVE users should reference CVE-2020-28050 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft Patch Tuesday Update Fixes 17 Critical Bugs ❌

Remote code execution vulnerabilities dominate this month’s security bulletin of warnings and patches.

πŸ“– Read

via "Threat Post".
πŸ•΄ Microsoft Patches Windows Kernel Flaw Under Active Attack πŸ•΄

This month's Patch Tuesday addressed a Windows zero-day in a release of 112 vulnerabilities, 17 of which are critical.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Claroty Details Vulnerabilities in Schneider PLCs πŸ•΄

The vulnerabilities in a common line of programmable logic controllers could allow attackers to gain control of industrial equipment.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-25268 β€Ό

Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25267 β€Ό

An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28408 β€Ό

The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28409 β€Ό

The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24367 β€Ό

Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24063 β€Ό

The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.

πŸ“– Read

via "National Vulnerability Database".