πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2019-14562 β€Ό

Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-14559 β€Ό

Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.

πŸ“– Read

via "National Vulnerability Database".
❌ Spotify Users Hit with Rash of Account Takeovers ❌

Users of the music streaming service were targeted by attackers using credential-stuffing approaches.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-0569 β€Ό

Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-14587 β€Ό

Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-14586 β€Ό

Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-14563 β€Ό

Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4783 β€Ό

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 189214.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-12352 β€Ό

Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-12351 β€Ό

Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-6939 β€Ό

Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users. If exploited, this could allow a malicious user to configure Site-Specific SAML settings and could lead to account takeover for users of that site. Tableau Server versions affected on both Windows and Linux are: 2018.2 through 2018.2.27, 2018.3 through 2018.3.24, 2019.1 through 2019.1.22, 2019.2 through 2019.2.18, 2019.3 through 2019.3.14, 2019.4 through 2019.4.13, 2020.1 through 2020.1.10, 2020.2 through 2020.2.7, and 2020.3 through 2020.3.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-14575 β€Ό

Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7928 β€Ό

A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects: MongoDB Inc. MongoDB Server v4.5 versions prior to 4.5.1; v4.4 versions prior to 4.4.1; v4.2 versions prior to 4.2.9; v4.0 versions prior to 4.0.20; v3.6 versions prior to 3.6.20.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4854 β€Ό

IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 190454.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4771 β€Ό

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 188993.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-20803 β€Ό

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.5; v3.6 versions prior to 3.6.10; v3.4 versions prior to 3.4.19.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Chinese APT Group Returns to Target Catholic Church & Diplomatic Groups πŸ•΄

APT group TA416 reemerges with new changes to its documented tool sets so it can continue launching espionage campaigns.

πŸ“– Read

via "Dark Reading".
❌ TA416 APT Rebounds With New PlugX Malware Variant ❌

The TA416 APT has returned in spear phishing attacks against a range of victims - from the Vatican to diplomats in Africa - with a new Golang version of its PlugX malware loader.

πŸ“– Read

via "Threat Post".
πŸ•΄ Manchester United Suffers Cyberattack πŸ•΄

Premier League soccer club says the attack didn't affect its website and app, and it doesn't appears to have exposed any fan or customer data either.

πŸ“– Read

via "Dark Reading".
❌ GoDaddy Employees Tricked into Compromising Cryptocurrency Sites ❌

β€˜Vishing’ attack on GoDaddy employees gave fraudsters access to cryptocurrency service domains NiceHash, Liquid.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-28927 β€Ό

There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user section from the admin panel, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

πŸ“– Read

via "National Vulnerability Database".