πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-21725 β€Ό

A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directories by performing specific operations, resulting in information leak. This affects: ZXHN H196Q V9.1.0C2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26971 β€Ό

A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system leading to partial system compromise.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26970 β€Ό

A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system leading to partial system compromise.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28050 β€Ό

Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26963 β€Ό

A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to full system compromise.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26965 β€Ό

A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection attacks against the AirWave instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35594 β€Ό

Zoho ManageEngine ADManager Plus before 7066 allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26968 β€Ό

A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victimÒ€ℒs browser in the context of the affected interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26967 β€Ό

A remote reflected cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of certain components of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victimÒ€ℒs browser in the context of the AirWave management interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28039 β€Ό

An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28502 β€Ό

This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29032 β€Ό

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prior to 9.4.621054022

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28038 β€Ό

An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issue exists because of an incomplete fix for CVE-2021-26931.

πŸ“– Read

via "National Vulnerability Database".
❌ Massive Supply-Chain Cyberattack Breaches Several Airlines ❌

The cyberattack on SITA, a nearly ubiquitous airline service provider, has compromised frequent-flyer data across many carriers.

πŸ“– Read

via "Threat Post".
πŸ•΄ 5 Ways Social Engineers Crack Into Human Beings πŸ•΄

These common human traits are the basic ingredients in the con-man's recipe for trickery.

πŸ“– Read

via "Dark Reading".
❌ WordPress Injection Anchors Widespread Malware Campaign ❌

Website admins should patch all plugins, WordPress itself and back-end servers as soon as possible.

πŸ“– Read

via "Threat Post".
❌ U.S. DoD Weapons Programs Lack β€˜Key’ Cybersecurity Measures ❌

The lack of cybersecurity requirements in weapons contracts from the Department of Defense opens the door for dangerous cyberattacks.

πŸ“– Read

via "Threat Post".
πŸ•΄ Microsoft Adopted an 'Aggressive' Strategy for Sharing SolarWinds Attack Intel πŸ•΄

Rob Lefferts, corporate vice president for Microsoft 365 Security in Security and Compliance, explains the company's approach to keeping its customers and the industry apprised and updated on its findings from the now-infamous attack.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Exchange Server Exploits Hit Retail, Government, Education πŸ•΄

Mandiant researchers identify a range of victims affected in attacks targeting newly reported Microsoft Exchange Server vulnerabilities.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-27254 β€Ό

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endpoint. This issue results from the use of hard-coded encryption key. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-12287.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27256 β€Ό

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided to apply_save.cgi. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12355.

πŸ“– Read

via "National Vulnerability Database".