πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-9277

MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9276

SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker's email, which contained a malicious payload. Therefore, users' passwords could be reset by using an XSS attack, as the password reset page did not need the current password.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10403 (chrome)

Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ BEC Groups Ramp Up Payroll Diversion Attacks πŸ•΄

Criminals are increasingly trying to defraud businesses by diverting payrolls of CEOs, other senior executives, Agari says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How the US Chooses Which Zero-Day Vulnerabilities to Stockpile πŸ•΄

When it comes to acceptable circumstances for government disclosure of zero-days, the new Vulnerabilities Equity Process might be the accountability practice security advocates have been waiting for.

πŸ“– Read

via "Dark Reading: ".
❌ Millions of Oklahoma Gov Files Exposed by Wide-Open Server ❌

The storage server was left open for about a week and exposed everything from sensitive FBI investigations to data related to patients with AIDS.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ Fortnite Players at Risk Via Epic Games Vulnerability πŸ•΄

Bugs in Epic Games' platform could let intruders take over players' accounts, view personal data, and/or buy in-game currency.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-3137

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-3136

A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. Affects BIND 9.8.0 -> 9.8.8-P1, 9.9.0 -> 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.0 -> 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0 -> 9.11.0-P3, 9.11.1b1->9.11.1rc1, 9.9.3-S1 -> 9.9.9-S8.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-3135

Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-1002152 (bodhi)

Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-9778

An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker could cause it to accept a query that possessed the required attributes. Please note: This vulnerability affects the "nxdomain-redirect" feature, which is one of two methods of handling NXDOMAIN redirection, and is only available in certain versions of BIND. Redirection using zones of type "redirect" is not affected by this vulnerability. Affects BIND 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P1.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Oklahoma Data Leak Compromises Years of FBI Data πŸ•΄

The Oklahoma Securities Commission accidentally leaked 3 TB of information, including data on years of FBI investigations.

πŸ“– Read

via "Dark Reading: ".
❌ Threatpost Survey Says: 2FA is Just Fine, But Go Ahead and Kill SMS ❌

Our reader poll showed overwhelming support for 2FA even in the wake of a bypass tool being released -- although lingering concerns remain.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ Malware Built to Hack Building Automation Systems πŸ•΄

Researchers dig into vulnerabilities in popular building automation systems, devices.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9281

Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.

πŸ“– Read

via "National Vulnerability Database".
⚠ Two charged with hacking company filings out of SEC’s EDGAR system ⚠

They're charged with phishing and inflicting malware to get into the EDGAR filing system, stealing thousands of filings, and selling access.

πŸ“– Read

via "Naked Security".
⚠ Change your password! VoIP provider leaves huge database exposed online ⚠

A researcher has discovered an exposed database containing gigabytes of call logs, SMS data, and internal system credentials belonging to US Voice-over-IP (VoIP) service provider VOIPo.com.

πŸ“– Read

via "Naked Security".
⚠ Microsoft font gives away forgery in bankruptcy case ⚠

In a case that could be straight out of a legal TV drama, a computing font has cost a couple two houses in a Canadian bankruptcy case.

πŸ“– Read

via "Naked Security".
❌ Cryptomining Malware Uninstalls Cloud Security Products ❌

New samples of cryptomining malware performs a never-before-seen function: uninstalling cloud security products.

πŸ“– Read

via "Threatpost | The first stop for security news".
⚠ Email crooks swindle woman out of $150K from home sale ⚠

She sent her bank account details three times, she said. Unfortunately, they wound up in crooks' hands, and her money wound up in their pockets.

πŸ“– Read

via "Naked Security".