๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ” $332 Million in GDPR Fines Issued to Date ๐Ÿ”

The figure, about 272.5 million euros, corresponds to 281,000 data breach notifications issued by regulators across Europe since GDPR went into effect.

๐Ÿ“– Read

via "Digital Guardian".
โŒ Rob Joyce to Take Over as NSA Cybersecurity Director โŒ

Joyce will replace Anne Neuberger, who is now deputy national security advisor for the incoming Biden administration.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด 4 Intriguing Email Attacks Detected by AI in 2020 ๐Ÿ•ด

Here's to the sneakiest of the sneaky. These clever phishing messages -- that standard validation measures often missed -- deserve proper dishonor.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2021-21263 โ€ผ

Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this will simply lead to no results being returned by the query builder; however, it is possible certain queries could be affected in a way that causes the query to return unexpected results.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-14409 โ€ผ

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-14410 โ€ผ

SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.

๐Ÿ“– Read

via "National Vulnerability Database".
โŒ DNSpooq Flaws Allow DNS Hijacking of Millions of Devices โŒ

Seven flaws in open-source software Dnsmasq could allow DNS cache poisoning attacks and remote code execution.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด SolarWinds Attack Underscores 'New Dimension' in Cyber-Espionage Tactics ๐Ÿ•ด

Meanwhile, Malwarebytes is the latest victim, Symantec discovers a fourth piece of malware used in the massive attack campaign, and FireEye Mandiant releases a free tool to help spot signs of the attack.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Microsoft to Launch 'Enforcement Mode' for Zerologon Flaw ๐Ÿ•ด

Enforcement mode for the Netlogon Domain Controller will be enabled by default with the Feb. 9 security update.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿฆฟ The aftermath of the SolarWinds breach: Organizations need to be more vigilant ๐Ÿฆฟ

Security experts say organizations are, and should, implement a number of changes ranging from how they vet vendors to handling application updates.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿ•ด Vulnerabilities in Popular DNS Software Allow Poisoning ๐Ÿ•ด

Seven flaws in DNSMasq have limited impact, but in combination they could be chained to create a multistaged attack.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2020-27264 โ€ผ

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which allows unauthenticated, physically proximate attackers to brute-force the keys via Bluetooth Low Energy.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-29598 โ€ผ

The My AIA SG application 1.2.6 for Android allows attackers to obtain user credentials via logcat because of excessive logging.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-27269 โ€ผ

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measures, which allows unauthenticated, physically proximate attackers to replay communication sequences via Bluetooth Low Energy.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-27256 โ€ผ

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to change insulin therapy settings.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-11997 โ€ผ

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-27266 โ€ผ

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-27268 โ€ผ

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass checks for default PINs via Bluetooth Low Energy.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-27258 โ€ผ

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows unauthenticated attackers to extract the pumpรขโ‚ฌโ„ขs keypad lock PIN via Bluetooth Low Energy.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-28707 โ€ผ

The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_chart_historical-wp.js in wp-content/plugins/stockdio-historical-chart/assets/ because the origin of a postMessage() event is not validated. The stockdio_eventer function listens for any postMessage event. After a message event is sent to the application, this function sets the "e" variable as the event and checks that the types of the data and data.method are not undefined (empty) before proceeding to eval the data.method received from the postMessage. However, on a different website. JavaScript code can call window.open for the vulnerable WordPress instance and do a postMessage(msg,'*') for that object.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-19362 โ€ผ

Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.

๐Ÿ“– Read

via "National Vulnerability Database".