πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-27192 β€Ό

BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allowed a local attacker to inject code into ForkLift. This would allow the attacker to run malicious code with escalated privileges through ForkLift's helper tool.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25705 β€Ό

A flaw in the way reply ICMP packets are limited in the Linux kernel functionality was found that allows to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well. Kernel versions before 5.10 may be vulnerable to this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13358 β€Ό

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13354 β€Ό

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-10776 β€Ό

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-11860 β€Ό

Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14389 β€Ό

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26406 β€Ό

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25833 β€Ό

Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. The vulnerability could be exploited to perform Persistent XSS attack.

πŸ“– Read

via "National Vulnerability Database".
❌ Some Apple Apps on macOS Big Sur Bypass Content Filters, VPNs ❌

Attackers can exploit the feature and send people’s data directly to remote servers, posing a privacy and security risk, researchers said.

πŸ“– Read

via "Threat Post".
πŸ•΄ Ransomware Operator Promotes Distributed Storage for Stolen Data πŸ•΄

The criminals behind the DarkSide ransomware-as-a-service operation say the system will be harder to take down.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-28687 β€Ό

The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7774 β€Ό

This affects the package y18n before 5.0.5. PoC by po6ix: const y18n = require('y18n')(); y18n.setLocale('__proto__'); y18n.updateLocale({polluted: true}); console.log(polluted); // true

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25746 β€Ό

QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable), aka wireless password visibility.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28647 β€Ό

In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7841 β€Ό

Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28688 β€Ό

The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
❌ Cisco Patches Critical Flaw After PoC Exploit Code Release ❌

A critical path-traversal flaw (CVE-2020-27130) exists in Cisco Security Manager that lays bare sensitive information to remote, unauthenticated attackers.

πŸ“– Read

via "Threat Post".
πŸ•΄ An Inside Look at an Account Takeover πŸ•΄

AI threat find: Phishing attack slips through email gateway and leads to large-scale compromise.

πŸ“– Read

via "Dark Reading".
πŸ›  GNU Privacy Guard 2.2.24 πŸ› 

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Security Risks Discovered in Tesla Backup Gateway πŸ•΄

Cybersecurity researchers report on the security and privacy risks of leaving a Tesla Backup Gateway exposed to the Internet.

πŸ“– Read

via "Dark Reading".