🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2018-18688

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.

📖 Read

via "National Vulnerability Database".
CVE-2020-25680

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

📖 Read

via "National Vulnerability Database".
🦿 How to quickly check to see if your Linux server is under a DDoS attack from a single IP address 🦿

Jack Wallen shows you an easy way to determine if your Linux server is under a DDoS attack and how to quickly stop it.

📖 Read

via "Tech Republic".
Fired Healthcare Exec Stalls Critical PPE Shipment for Months

A fired Stradis Healthcare employee sought revenge by tampering with shipping data for desperately needed healthcare PPE.

📖 Read

via "Threat Post".
🕴 Ransomware Victims' Data Published via DDoSecrets 🕴

Activists behind Distributed Denial of Secrets has shared 1TB of data pulled from Dark Web sites where it was shared by ransomware attackers.

📖 Read

via "Dark Reading".
🕴 How the Shady Zero-Day Sales Game Is Evolving 🕴

Zero-day vulns are cold, while access-as-a-service is hot. Here's how black market (and gray market) deals go down.

📖 Read

via "Dark Reading".
🔏 SolarWinds Hackers Hit DOJ, US Court Systems 🔏

Federal agencies impacted by last year's supply chain attack on SolarWinds continue to pile up.

📖 Read

via "Digital Guardian".
🕴 Even Small Nations Have Jumped into the Cyber Espionage Game 🕴

While the media tends to focus on the Big 5 nation-state cyber powers, commercial spyware has given smaller countries sophisticated capabilities, as demonstrated by a "zero-click" iMessage exploit that targeted journalists last year.

📖 Read

via "Dark Reading".
🦿 Homebrew: How to install vulnerability tools on macOS 🦿

We'll guide you through the process of using Homebrew package manager to install security tools on macOS to assess vulnerabilities and the security posture of the devices on your network.

📖 Read

via "Tech Republic".
🦿 10 fastest-growing cybersecurity skills to learn in 2021 🦿

People with experience in application development security are in the highest demand but cloud expertise commands the biggest paycheck.

📖 Read

via "Tech Republic".
Nvidia Warns Windows Gamers of High-Severity Graphics Driver Flaws

In all, Nvidia patched flaws tied to 16 CVEs across its graphics drivers and vGPU software, in its first security update of 2021.

📖 Read

via "Threat Post".
Biden to Appoint Cybersecurity Advisor to NSC – Report

Anne Neuberger will join the National Security Council, according to sources.

📖 Read

via "Threat Post".
🕴 State Dept. to Create New Cybersecurity & Technology Agency 🕴

Bureau of Cyberspace Security and Emerging Technologies (CSET) will serve as diplomatic arm for US cybersecurity interests.

📖 Read

via "Dark Reading".
🕴 FireEye's Mandia: 'Severity-Zero Alert' Led to Discovery of SolarWinds Attack 🕴

CEO Kevin Mandia shared some details on how his company rooted out the major cyberattack campaign affecting US government and corporate networks.

📖 Read

via "Dark Reading".
🦿 Homebrew: How to install exploit tools on macOS 🦿

We'll guide you through the process of using Homebrew package manager to install security tools on macOS to exploit vulnerabilities found in your Apple equipment.

📖 Read

via "Tech Republic".
CVE-2019-18642

Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any user to change account details of any other user. This vulnerability could be used to change the email address of another account, even the administrator account. Upon changing another account's email address, performing a password reset to the new email address could allow an attacker to take over any account.

📖 Read

via "National Vulnerability Database".
CVE-2020-13452

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

📖 Read

via "National Vulnerability Database".
CVE-2020-13450

A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program behavior, or code execution.

📖 Read

via "National Vulnerability Database".
CVE-2021-23242

MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.

📖 Read

via "National Vulnerability Database".
CVE-2020-13449

A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.

📖 Read

via "National Vulnerability Database".
CVE-2020-17500

Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection issue that will result in unauthenticated remote code execution in the username and password fields of the logon prompt. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.

📖 Read

via "National Vulnerability Database".