πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Microsoft's Power BI gets new tools to prevent leakage of confidential data 🦿

Information protection makes sure that only people with permissions see data in Power BI, while retaining the ability to share top-level trends, balancing productivity and security.

πŸ“– Read

via "Tech Republic".
🦿 Top 5 things to know about adversarial attacks 🦿

Machine learning is helpful to many organizations in the tech industry, but it can have a downside. Tom Merritt lists five things to know about adversarial attacks.

πŸ“– Read

via "Tech Republic".
🦿 Adversarial attacks: 5 things to know 🦿

Machine learning is helpful to many organizations in the tech industry, but it can have a downside. Tom Merritt lists five things to know about adversarial attacks.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-26559 β€Ό

Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36003 β€Ό

The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26809 β€Ό

PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35339 β€Ό

In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-12365 β€Ό

Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of service via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27362 β€Ό

The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25779 β€Ό

Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36002 β€Ό

Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id and file parameters where attackers can obtain sensitive database information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25780 β€Ό

An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including PHP files, which could result in command execution and obtaining a shell.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22173 β€Ό

Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27224 β€Ό

The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26697 β€Ό

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to that endpoint and even after can just get some metadata about a DAG and a Task. This issue affects Apache Airflow 2.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22174 β€Ό

Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Breach Etiquette: How to Mind Your Manners When It Matters πŸ•΄

Panic-stricken as you may be in the face of a cyberattack, keeping calm and, perhaps most importantly, responding appropriately are critical to limiting the damage.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Enterprise Windows Threats Drop as Mac Attacks Rise: Report πŸ•΄

An analysis of 2020 malware activity indicates businesses should be worried about internal hack tools, ransomware, and spyware in the year ahead.

πŸ“– Read

via "Dark Reading".
⚠ β€œScamClub” gang outed for exploiting iPhone browser bug to spew ads ⚠

Stay away from popup surveys that want personal data. Tell your friends...

πŸ“– Read

via "Naked Security".
⚠ How one man silently infiltrated dozens of high-tech networks ⚠

Ever counted how many external source code dependencies your fancy new software product has? Be prepared for a surprise!

πŸ“– Read

via "Naked Security".
⚠ Romance scams at all-time high: here’s what you need to know ⚠

It's heartbreaking to get sucked into a romance scam, or to watch a friend or family member getting sucked in. Here's what to do...

πŸ“– Read

via "Naked Security".