πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-28088 β€Ό

Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21381 β€Ό

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to gain access to files that would not ordinarily be allowed by the app's permissions. By putting the special tokens `@@` and/or `@@u` in the Exec field of a Flatpak app's .desktop file, a malicious app publisher can trick flatpak into behaving as though the user had chosen to open a target file with their Flatpak app, which automatically makes that file available to the Flatpak app. This is fixed in version 1.10.2. A minimal solution is the first commit "`Disallow @@ and @@U usage in desktop files`". The follow-up commits "`dir: Reserve the whole @@ prefix`" and "`dir: Refuse to export .desktop files with suspicious uses of @@ tokens`" are recommended, but not strictly required. As a workaround, avoid installing Flatpak apps from untrusted sources, or check the contents of the exported `.desktop` files in `exports/share/applications/*.desktop` (typically `~/.local/share/flatpak/exports/share/applications/*.desktop` and `/var/lib/flatpak/exports/share/applications/*.desktop`) to make sure that literal filenames do not follow `@@` or `@@u`.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14987 β€Ό

An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. An attacker must use an AST transforming annotation such as @Grab.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27679 β€Ό

Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26776 β€Ό

CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.

πŸ“– Read

via "National Vulnerability Database".
🦿 Hackers update Gootkit RAT to use Google searches and discussion forums to deliver malware 🦿

Security analysts and an SEO expert explain how this new approach uses legitimate websites to trick users into downloading infected files.

πŸ“– Read

via "Tech Republic".
πŸ” Virginia Passes Consumer Data Protection Act πŸ”

Virginia’s Consumer Data Protection Act (CDPA) is first major state privacy law since California's. Under the law, organizations will need to implement reasonable security practices to protect sensitive data.

πŸ“– Read

via "Digital Guardian".
β€Ό CVE-2020-14989 β€Ό

An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29045 β€Ό

The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14988 β€Ό

An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML elements, the translations menu via the foldername parameter, the author page via the link URL, or the upload image functionality via an SVG document containing JavaScript.

πŸ“– Read

via "National Vulnerability Database".
❌ TrickBot Takes Over, After Cops Kneecap Emotet ❌

TrickBot rises to top threat in February, overtaking Emotet in Check Point’s new index.

πŸ“– Read

via "Threat Post".
❌ Ransomware Attack Strikes Spain’s Employment Agency ❌

Reports say that the agency in charge of managing Spain's unemployment benefits has been hit by the Ryuk ransomware.

πŸ“– Read

via "Threat Post".
πŸ•΄ Does XDR Mark the Spot? 6 Questions to Ask πŸ•΄

Extended detection and response technology goes well beyond endpoint management to provide visibility into networks, servers, cloud, and applications. Could it be the answer to your security challenges?

πŸ“– Read

via "Dark Reading".
🦿 How to install and configure 2FA on AlmaLinux 🦿

Jack Wallen walks you through the process of enabling two-factor authentication on the new fork of CentOS, AlmaLinux.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Molson Coors Beer Operations Halted by Hack πŸ•΄

No details yet disclosed on the cyberattack.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Network Pivots, Patch Bypasses: Exploits Hit Hard in 2020 πŸ•΄

An analysis of 50 vulnerabilities finds a spectrum of risk, from widespread vulnerabilities exploited by a variety of attackers to serious issues that will likely be exploited in 2021.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-28154 β€Ό

** DISPUTED ** Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which manipulates the readFile and writeFile APIs. NOTE: the vendor states "The way we secured the app is that it does not allow any remote scripts to be opened, no unsafe scripts to be evaluated, no remote sites to be browsed."

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24983 β€Ό

An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST request made to the DashboardBuilder within the target web application. This request will utilise the target admin session and perform the authenticated request (to change the Dashboard name) as if the victim had done so themselves, aka CSRF.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22710 β€Ό

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22714 β€Ό

A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or allow for remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22712 β€Ό

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to IGSS Definition due to an unchecked pointer address.

πŸ“– Read

via "National Vulnerability Database".