🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
VMware Rolls a Fix for Formerly Critical Zero-Day Bug

VMware has issued a full patch and revised the severity level of the NSA-reported vulnerability to "important."

📖 Read

via "Threat Post".
🔏 Friday Five 12/4 🔏

Trickbot's new tricks, attacking vaccine cold chains, and CFAA in front of the Supreme Court - catch up on all of the week's infosec news with the Friday Five!

📖 Read

via "Digital Guardian".
CVE-2020-27767

A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

📖 Read

via "National Vulnerability Database".
CVE-2020-27766

A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.8-69.

📖 Read

via "National Vulnerability Database".
CVE-2020-27765

A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

📖 Read

via "National Vulnerability Database".
CVE-2020-27771

In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts the return value of GetPixelIndex() to ssize_t type to avoid this bug. This undefined behavior could be triggered when ImageMagick processes a crafted pdf file. Red Hat Product Security marked this as Low severity because although it could potentially lead to an impact to application availability, no specific impact was demonstrated in this case. This flaw affects ImageMagick versions prior to 7.0.9-0.

📖 Read

via "National Vulnerability Database".
CVE-2020-27408

OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.

📖 Read

via "National Vulnerability Database".
CVE-2020-27409

OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.

📖 Read

via "National Vulnerability Database".
CVE-2020-27770

Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.

📖 Read

via "National Vulnerability Database".
🦿 Most used passwords for 2020: The internet's favorite curse word, name, food, and team 🦿

CyberNews analyzed more than 15 billion passwords; if your favorite one is at the top of the list, it's time to change right now.

📖 Read

via "Tech Republic".
🕴 Intel Doubles Down on Emerging Technologies for Sharing and Using Data Securely 🕴

Homomorphic encryption and federated learning could allow groups to share data and analysis while protecting the actual information.

📖 Read

via "Dark Reading".
CVE-2020-25461

Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of service (SEGV).

📖 Read

via "National Vulnerability Database".
CVE-2020-25463

Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service (SEGV).

📖 Read

via "National Vulnerability Database".
CVE-2020-25464

Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially initialized because the stack overflowed while creating the frame. This leads to a crash in the code sending the stack frame to the debugger.

📖 Read

via "National Vulnerability Database".
CVE-2020-25465

Null Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK before OS200908 causes a denial of service (SEGV).

📖 Read

via "National Vulnerability Database".
CVE-2020-25462

Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK before OS200903.

📖 Read

via "National Vulnerability Database".
Novel Online Shopping Malware Hides in Social-Media Buttons

The skimmer steals credit-card data, using steganography to hide in plain sight in seemingly benign images.

📖 Read

via "Threat Post".
🕴 BECs and EACs: What's the Difference? 🕴

Email accounts are common targets for attack. Understanding how attack types differ is critical for successful defense.

📖 Read

via "Dark Reading".
High-Severity Chrome Bugs Allow Browser Hacks

Desktop versions of the browser received a total of eight fixes, half rated high-severity.

📖 Read

via "Threat Post".
CVE-2020-25449

Cross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column.

📖 Read

via "National Vulnerability Database".
🕴 Kmart Hit by Egregor Ransomware 🕴

Egregor is also behind recent attacks on UbiSoft and Barnes & Noble.

📖 Read

via "Dark Reading".