πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-29382 β€Ό

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. A hardcoded RSA private key (specific to V1600D, V1600G1, and V1600G2) is contained in the firmware images.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29375 β€Ό

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. An low-privileged (non-admin) attacker can use a hardcoded password (4ef9cea10b2362f15ba4558b1d5c081f) to create an admin user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29379 β€Ό

An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating the firmware, the update script starts a telnetd -l /bin/sh process that does not require authentication for TELNET access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29377 β€Ό

An issue was discovered on V-SOL V1600D V2.03.69 OLT devices. The string K0LTdi@gnos312$ is compared to the password provided by the the remote attacker. If it matches, access is provided.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29378 β€Ό

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. It is possible to elevate the privilege of a CLI user (to full administrative access) by using the password !j@l#y$z%x6x7q8c9z) for the enable command.

πŸ“– Read

via "National Vulnerability Database".
⚠ Home Wi-Fi security tips – 5 things to check ⚠

5 checks to make sure your home Wi-Fi is secure

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-27660 β€Ό

SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25624 β€Ό

hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29127 β€Ό

An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang=en is visited from a different web browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27659 β€Ό

Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter.

πŸ“– Read

via "National Vulnerability Database".
⚠ Naked Security Live – The Gift Card hackers ⚠

Here's the latest Naked Security Live video - please watch and share with your friends...

πŸ“– Read

via "Naked Security".
❌ MacOS Users Targeted By OceanLotus Backdoor ❌

The new backdoor comes with multiple payloads and new detection evasion tactics.

πŸ“– Read

via "Threat Post".
❌ Pandemic, A Driving Force in 2021 Financial Crime ❌

Ransomware gangs with zero-days and more players overall will characterize financially motivated cyberattacks next year.

πŸ“– Read

via "Threat Post".
🦿 Cybersecurity report: Average household hit with 104 threats each month 🦿

The most vulnerable devices include laptops, computers, smartphones and tablets, networked cameras and storage devices, and streaming video devices, a new report found.

πŸ“– Read

via "Tech Republic".
🦿 How to get Linux to see the FEITIAN fingerprint reader for FIDO2 security 🦿

If you've purchased a FEITIAN FIDO2 device and can't seem to get it working with Linux, Jack Wallen shows you how.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-29364 β€Ό

In NetArt News Lister 1.0.0, news headlines are vulnerable to stored XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25537 β€Ό

File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29392 β€Ό

The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical access can unlock the password manager without knowing the master password set by the user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28926 β€Ό

ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29390 β€Ό

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

πŸ“– Read

via "National Vulnerability Database".
❌ Digitally Signed Bandook Trojan Reemerges in Global Spy Campaign ❌

A strain of the 13-year old backdoor Bandook trojan has been spotted in an espionage campaign.

πŸ“– Read

via "Threat Post".