πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Failing Toward Zero: Why Your Security Needs to Fail to Get Better πŸ•΄

Each security incident should lead to a successive reduction in future incidences of the same type. Organizations that fail toward zero embrace failure and learn from their mistakes.

πŸ“– Read

via "Dark Reading".
❌ ThreatList: Cyber Monday Looms – But Shoppers Oblivious to Top Retail Threats ❌

Online shoppers are blissfully unaware of credit card skimming threats and malicious shopping apps as they head into this year's Black Friday and Cyber Monday holiday shopping events.

πŸ“– Read

via "Threat Post".
❌ Cybersecurity Predictions for 2021: Robot Overlords No, Connected Car Hacks Yes ❌

While 2021 will present evolving threats and new challenges, it will also offer new tools and technologies that will we hope shift the balance towards the defense.

πŸ“– Read

via "Threat Post".
πŸ•΄ 5 Signs Someone Might be Taking Advantage of Your Security Goodness πŸ•΄

Not everyone in a security department is acting in good faith, and they'll do what they can to bypass those who do. Here's how to spot them.

πŸ“– Read

via "Dark Reading".
❌ TurkeyBombing Puts New Twist on Zoom Abuse ❌

Threat actors already stole nearly 4,000 credentials before the holiday was even over, according to report.

πŸ“– Read

via "Threat Post".
πŸ•΄ Test πŸ•΄

A security researcher explains the dangers of poor visibility in the cloud and a new strategy to evaluate IAM exposure in Google Cloud Platform.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-28921 β€Ό

An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write to arbitrary Model Specific Registers (MSRs). This could lead to arbitrary Ring-0 code execution and escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19873 β€Ό

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the AprolSqlServer DBMS by bypassing authentication, a different vulnerability than CVE-2019-16356 and CVE-2019-9983.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19874 β€Ό

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerability than CVE-2019-16364.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27746 β€Ό

Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15685 β€Ό

Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27745 β€Ό

Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15684 β€Ό

Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7780 β€Ό

This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed with an empty X-XSRF-TOKEN header and an empty XSRF-TOKEN cookie.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15680 β€Ό

In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15686 β€Ό

Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal usersÒ€ℒ cookies.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19877 β€Ό

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive information outside the working directory via Directory Traversal attacks against AprolSqlServer, a different vulnerability than CVE-2019-16357.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19875 β€Ό

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus executes with root privileges, a different vulnerability than CVE-2019-16364.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15681 β€Ό

In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28922 β€Ό

An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write arbitrary physical memory. This could lead to arbitrary Ring-0 code execution and escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25014 β€Ό

A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.

πŸ“– Read

via "National Vulnerability Database".