πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Microsoft Patch Tuesday Fixes 82 CVEs, Internet Explorer Zero-Day πŸ•΄

The monthly rollout follows last week's emergency Microsoft Exchange Server patch covering seven CVEs, four of which are under attack.

πŸ“– Read

via "Dark Reading".
❌ Microsoft Patch Tuesday Updates Fix 14 Critical Bugs ❌

Microsoft's regularly scheduled March Patch Tuesday updates address 89 CVEs overall.

πŸ“– Read

via "Threat Post".
❌ Dark Web Markets for Stolen Data See Banner Sales ❌

Despite an explosion in the sheer amount of stolen data available on the Dark Web, the value of personal information is holding steady, according to the 2021 Dark Web price index from Privacy Affairs. That leaves these thriving dirty data dealers in a familiar predicament β€” they need to lock down their growing businesses for […]

πŸ“– Read

via "Threat Post".
🦿 How to enable Android's Password Checkup feature 🦿

Google has released a new password checker for Android. Find out how to enable and use this security feature on your Android device.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-23273 β€Ό

The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a stored Cross Site Scripting (XSS) attack on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 10.3.3 and below, versions 10.10.0, 10.10.1, and 10.10.2, versions 10.7.0, 10.8.0, 10.9.0, 11.0.0, and 11.1.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions 11.1.0 and below, TIBCO Spotfire Desktop: versions 10.3.3 and below, versions 10.10.0, 10.10.1, and 10.10.2, versions 10.7.0, 10.8.0, 10.9.0, 11.0.0, and 11.1.0, and TIBCO Spotfire Server: versions 10.3.11 and below, versions 10.10.0, 10.10.1, 10.10.2, and 10.10.3, versions 10.7.0, 10.8.0, 10.8.1, 10.9.0, 11.0.0, and 11.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28115 β€Ό

The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28116 β€Ό

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

πŸ“– Read

via "National Vulnerability Database".
❌ Apple’s Device Location-Tracking System Could Expose User Identities ❌

Researchers have identified two vulnerabilities in the company’s crowd-sourced Offline Finding technology that could jeopardize its promise of privacy.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-28119 β€Ό

Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal API.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3310 β€Ό

Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29238 β€Ό

An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

πŸ“– Read

via "National Vulnerability Database".
⚠ Serious Security: Webshells explained in the aftermath of HAFNIUM attacks ⚠

Webshells explained, with some (safe) examples you can try at home if you want to learn more.

πŸ“– Read

via "Naked Security".
🦿 How your remote employees may be sharing sensitive data 🦿

A majority of employees said they share sensitive information through messaging and collaboration tools, says Veritas.

πŸ“– Read

via "Tech Republic".
❌ Breach Exposes Verkada Security Camera Footage at Tesla, Cloudflare ❌

Surveillance footage from companies such as Tesla as well as hospitals, prisons, police departments and schools was accessed in the hack.

πŸ“– Read

via "Threat Post".
πŸ•΄ Call Recorder iPhone App Flaw Uncovered πŸ•΄

Researcher finds thousands of recorded calls easily accessible to others.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-28007 β€Ό

Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in register.php through the name parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23722 β€Ό

An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23721 β€Ό

An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24791 β€Ό

FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28705 β€Ό

FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /pages/delete/3.

πŸ“– Read

via "National Vulnerability Database".