πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-28381 β€Ό

A vulnerability has been identified in Solid Edge (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write into uninitialized memory. An attacker could leverage this vulnerability to execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23930 β€Ό

OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23936 β€Ό

OX App Suite through 7.10.4 allows XSS via the subject of a task.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28395 β€Ό

A vulnerability has been identified in SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28391 β€Ό

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions). Devices create a new unique key upon factory reset, except when used with C-PLUG. When used with C-PLUG the devices use the hardcoded private RSA-key shipped with the firmware-image. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23927 β€Ό

OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23932 β€Ό

OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26990 β€Ό

A vulnerability has been identified in JT2Go (All Versions < V13.1.0), JT2Go (V 13.1.0), Teamcenter Visualization (All Versions < V13.1.0), Teamcenter Visualization (V 13.1.0). Affected applications lack proper validation of user-supplied data when parsing ASM files. A crafted ASM file can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36191 β€Ό

JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28374 β€Ό

In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.

πŸ“– Read

via "National Vulnerability Database".
❌ CISOs Prep For COVID-19 Exposure Notification in the Workplace ❌

Security teams are preparing for the inevitable return to the workplace - and the privacy implications of exposure notification apps that companies may need to adopt.

πŸ“– Read

via "Threat Post".
πŸ•΄ The Data-Centric Path to Zero Trust πŸ•΄

Data is an organization's most valuable asset, so a data-centric approach would provide the best value for organizations, now and in the future.

πŸ“– Read

via "Dark Reading".
⚠ Home schooling – how to stay secure ⚠

Whether you’re new to home schooling or an old hand, it’s worth taking a moment to ensure you’re doing it securely.

πŸ“– Read

via "Naked Security".
❌ Sophisticated Hacks Against Android, Windows Reveals Zero-Day Trove ❌

Watering-hole attacks executed by β€˜experts’ exploited Chrome, Windows and Android flaws and were carried out on two servers.

πŸ“– Read

via "Threat Post".
🦿 CES 2021: All of the business tech news you need to know 🦿

Don't miss TechRepublic's CES 2021 coverage, which includes product announcements from Lenovo, Samsung, LG, and Dell about PCs, laptops, software, robots, monitors, and TVs.

πŸ“– Read

via "Tech Republic".
❌ Hackers Leak Stolen Pfizer-BioNTech COVID-19 Vaccine Data ❌

On the heels of a cyberattack on the EMA, cybercriminals have now leaked Pfizer and BioNTech COVID-19 vaccine data on the internet.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-21607 β€Ό

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21606 β€Ό

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21614 β€Ό

Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21604 β€Ό

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21608 β€Ό

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.

πŸ“– Read

via "National Vulnerability Database".