πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-6111 β€Ό

An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 16.000, Series B FRN 15.002, Series B FRN 15.000, Series B FRN 14.000, Series B FRN 13.000, Series B FRN 12.000, Series B FRN 11.000 and Series B FRN 10.000. A specially crafted packet can cause a major error, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
❌ Cyberattacks Target COVID-19 Vaccine β€˜Cold-Chain’ Orgs ❌

Cybercriminals try to steal the credentials of top companies associated with the COVID-19 vaccine supply chain in an espionage effort.

πŸ“– Read

via "Threat Post".
🦿 Popular Android apps still vulnerable to patched security flaw 🦿

Cybercriminals can exploit the at-risk apps to steal login credentials, passwords, financial details, and text messages, says Check Point.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-2320 β€Ό

Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28937 β€Ό

OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2324 β€Ό

Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2322 β€Ό

Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28939 β€Ό

OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14318 β€Ό

A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2321 β€Ό

A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a project.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2323 β€Ό

Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28938 β€Ό

OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.

πŸ“– Read

via "National Vulnerability Database".
❌ Reverse Engineering Tools: Evaluating the True Cost ❌

Breaking down the true cost of software tools in the context of reverse engineering and debugging may not be as clear-cut as it appears.

πŸ“– Read

via "Threat Post".
❌ DeathStalker APT Spices Things Up with PowerPepper Malware ❌

A raft of obfuscation techniques turn the heat up for the hacking-for-hire operation.

πŸ“– Read

via "Threat Post".
πŸ•΄ Researchers Bypass Next-Generation Endpoint Protection πŸ•΄

Machine learning-based products can be tricked to classify malware as a legitimate file, new findings show.

πŸ“– Read

via "Dark Reading".
πŸ•΄ US Officials Take Action Against 2,300 Money Mules πŸ•΄

Eight federal law enforcement agencies participated in the Money Mule Initiative, a global crackdown on money laundering.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cloud Security Threats for 2021 πŸ•΄

Most of these issues can be remediated, but many users and administrators don't find out about them until it's too late.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-13524 β€Ό

An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corruption. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27760 β€Ό

In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to application availability. The patch uses the `PerceptibleReciprocal()` to prevent the divide-by-zero from occurring. This flaw affects ImageMagick versions prior to ImageMagick 7.0.8-68.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13542 β€Ό

A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an attacker can either replace the service binary or replace DLL files loaded by the service, both which get executed by a service thus executing arbitrary commands with System privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27763 β€Ό

A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.8-68.

πŸ“– Read

via "National Vulnerability Database".