🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2020-27557

Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text credentials.

📖 Read

via "National Vulnerability Database".
CVE-2020-21665

In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malicious parameter can be passed for SQL injection.

📖 Read

via "National Vulnerability Database".
Zoom Takes on Zoom-Bombers Following FTC Settlement

The videoconferencing giant has upped the ante on cybersecurity with three fresh disruption controls.

📖 Read

via "Threat Post".
🕴 Chart: Undisputed Increase in Paid Claims 🕴

While the number of enterprises that hold cyber insurance might not have increased significantly over the past year, the number of enterprises that have successfully filed a breach insurance claim has.

📖 Read

via "Dark Reading".
🕴 Researchers Scan for Supply-Side Threats in Open Source 🕴

A recent project to scan the main Python repository's 268,000 packages found only a few potentially malicious programs, but work earlier this year uncovered hundreds of instances of malware.

📖 Read

via "Dark Reading".
🕴 To Pay or Not to Pay: Responding to Ransomware From a Lawyer's Perspective 🕴

The threat of data extortion adds new layers of risk when determining how to respond to a ransomware attack.

📖 Read

via "Dark Reading".
CVE-2020-26701

Cross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT Platform v1.2.0 allows remote attackers to inject malicious web scripts or HTML Injection payloads via the Description parameter.

📖 Read

via "National Vulnerability Database".
CVE-2020-13351

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

📖 Read

via "National Vulnerability Database".
CVE-2020-25400

Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token.

📖 Read

via "National Vulnerability Database".
CVE-2020-13350

CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.

📖 Read

via "National Vulnerability Database".
COVID-19 Antigen Firm Hit by Malware Attack

Global biotech firm Miltenyi, which supplies key components necessary for COVID-19 treatment research, has been battling a malware attack.

📖 Read

via "Threat Post".
🦿 The team behind the Essential PH-1 is back, and privacy is their focus 🦿

A key member of the now-defunct Essential company has returned, and privacy is his goal. Jack Wallen digs in to try and make sense of what's to come with OSOM.

📖 Read

via "Tech Republic".
🔏 Google Fixes Zero Days, NAT Slipstream Attack, in Chrome 🔏

Just days after fixing two zero day vulnerabilities, Google has rolled out yet another version of its Chrome browser, resolving a fix for last month's NAT Slipstream attack.

📖 Read

via "Digital Guardian".
🦿 Google Authenticator: How to move from one iPhone or Android device to another 🦿

If you migrated to a different iPhone or Android device and need to transfer Google Authenticator to the new hardware, follow these steps.

📖 Read

via "Tech Republic".
CVE-2020-25988

UPNP/Freeciv Service on port 5555 in Genexis Platinum 4410 Router V2.1 has an action 'X_GetAccess' which leaks the credentials of 'admin' account if the attacker is on the same network.

📖 Read

via "National Vulnerability Database".
CVE-2020-28139

SourceCodester Online Clothing Store 1.0 is affected by a cross-site scripting (XSS) vulnerability via a Offer Detail field in offer.php.

📖 Read

via "National Vulnerability Database".
CVE-2020-13349

An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

📖 Read

via "National Vulnerability Database".
CVE-2020-28140

SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php.

📖 Read

via "National Vulnerability Database".
CVE-2020-28133

An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.

📖 Read

via "National Vulnerability Database".
CVE-2020-26405

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

📖 Read

via "National Vulnerability Database".
CVE-2020-28138

SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.

📖 Read

via "National Vulnerability Database".