πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-24360 β€Ό

An issue with ARP packets in AristaÒ€ℒs EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash, followed by a device reload. The affected Arista EOS versions are: 4.24.2.4F and below releases in the 4.24.x train; 4.23.4M and below releases in the 4.23.x train; 4.22.6M and below releases in the 4.22.x train.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27837 β€Ό

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35730 β€Ό

linkref_addindex in rcube_string_replacer.php in Roundcube Webmail before 1.4.10 allows XSS via a crafted email message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35612 β€Ό

An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35615 β€Ό

An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25507 β€Ό

An incorrect permission assignment (chmod 777) of /etc/environment during the installation script of No Magic TeamworkCloud 18.0 through 19.0 allows any local unprivileged user to write to /etc/environment. An attacker can escalate to root by writing arbitrary code to this file, which would be executed by root during the next login, reboot, or sourcing of the environment.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-15898 β€Ό

In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version 4.21.4.1F and below releases in the 4.21.x train; EOS X-Series versions 4.21.11M and below releases in the 4.21.x train; 4.22.6M and below releases in the 4.22.x train; 4.23.4M and below releases in the 4.23.x train; 4.24.2.1F and below releases in the 4.24.x train.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35769 β€Ό

miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25847 β€Ό

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Security Pros Reflect on 2020 πŸ•΄

Eight cybersecurity leaders go deep on their most valuable (and very human) takeaways from a year like no other we've known.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Mac Attackers Remain Focused Mainly on Adware, Fooling Users πŸ•΄

Despite reports that Macs have encountered more threats than Windows systems, the platform still sees far fewer exploits and malware - including ransomware.

πŸ“– Read

via "Dark Reading".
❌ 2020 Work-for-Home Shift: What We Learned ❌

Threatpost explores 5 big takeaways from 2020 -- and what they mean for 2021.

πŸ“– Read

via "Threat Post".
🦿 How companies can use automation to secure cloud data 🦿

Data automation allows companies to conduct operations more consistently, securely, and reliably. Learn how one company tackled the challenges.

πŸ“– Read

via "Tech Republic".
πŸ•΄ India: A Growing Cybersecurity Threat πŸ•΄

Geopolitical tensions and a dramatic rise in offensive and defensive cyber capabilities lead India to join Iran, Russia, China, and North Korea as a top nation-state adversary.

πŸ“– Read

via "Dark Reading".
❌ Japanese Aerospace Firm Kawasaki Warns of Data Breach ❌

The Japanese aerospace manufacturer said that starting in June, overseas unauthorized access to its servers may have compromised customer data.

πŸ“– Read

via "Threat Post".
❌ 6 Questions Attackers Ask Before Choosing an Asset to Exploit ❌

David β€œmoose” Wolpoff at Randori explains how hackers pick their targets, and how understanding "hacker logic" can help prioritize defenses.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-5801 β€Ό

An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5802 β€Ό

An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5806 β€Ό

An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5807 β€Ό

An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer (FTDiagViewer.exe) to view the log entry. Observed in FactoryTalk Diagnostics 6.11. All versions of FactoryTalk Diagnostics are affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29475 β€Ό

nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time any user will go to that page of the website, the XSS triggers and attacker can able to steal the cookie according to the crafted payload.

πŸ“– Read

via "National Vulnerability Database".