πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Feds Pinpoint Russia as β€˜Likely’ Culprit Behind SolarWinds Attack ❌

The widespread compromise affecting key government agencies is ongoing, according to the U.S. government.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-4336 β€Ό

IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 177932.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-8884 β€Ό

rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-10657 β€Ό

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAlertRules feature. The vulnerability allows a remote attacker (with admin or config-admin privileges in the console) to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-10658 β€Ό

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteImage API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-10655 β€Ό

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouse API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-10656 β€Ό

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36170 β€Ό

The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26759 β€Ό

clickhouse-driver before 0.1.5 allows a malicious clickhouse server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, due to a buffer overflow.

πŸ“– Read

via "National Vulnerability Database".
🦿 US government fingers Russia for SolarWinds-based cyberattack 🦿

A joint statement from the FBI, NSA, and other federal agencies says the cyber incident was likely Russian in origin.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-27283 β€Ό

An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13544 β€Ό

An exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021Ò€ℒs TextMaker application. A specially crafted document can cause the document parser to sign-extend a length used to terminate a loop, which can later result in the loopÒ€ℒs index being used to write outside the bounds of a heap buffer during the reading of file data. An attacker can entice the victim to open a document to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13545 β€Ό

An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021Ò€ℒs TextMaker application. A specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based memory corruption. An attacker can entice the victim to open a document to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36174 β€Ό

The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27285 β€Ό

The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36172 β€Ό

The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36175 β€Ό

The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36173 β€Ό

The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-8160 β€Ό

MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via the URL path. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36176 β€Ό

The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36177 β€Ό

RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size.

πŸ“– Read

via "National Vulnerability Database".