πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2006-0016 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
❌ iPhone Wi-Fi Crushed by Weird Network ❌

… until you reset network settings and stop connecting to a weirdly named network, that is. FUD is spreading. iOS Wi-Fi demolition is not.

πŸ“– Read

via "Threat Post".
πŸ•΄ Fintech at SaaS Speed πŸ•΄



πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-0522 β€Ό

In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-174182139

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0520 β€Ό

In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-176237595

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19510 β€Ό

Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32697 β€Ό

neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted without invoking any validators. Form state is secured with an HMAC that is still verified. That means that this issue can only be exploited if Form Finishers cause side effects even if no form values have been sent. Form Finishers can be adjusted in a way that they only execute an action if the submitted form contains some expected data. Alternatively a custom Finisher can be added as first finisher. This regression was introduced with https://github.com/neos/form/commit/049d415295be8d4a0478ccba97dba1bb81649567

πŸ“– Read

via "National Vulnerability Database".
❌ Embryology Data Breach Follows Fertility Clinic Ransomware Hit ❌

Approximately 38,000 of RBA's customers had their embryology data stolen by a ransomware gang.

πŸ“– Read

via "Threat Post".
πŸ•΄ Baltimore County Public Schools' Ransomware Recovery Tops $8M πŸ•΄

The school district has spent seven months and a reported $8.1 million recovering from the November attack.

πŸ“– Read

via "Dark Reading".
❌ Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft ❌

Chipmaker patches nine high-severity bugs in its Jetson SoC framework tied to the way it handles low-level cryptographic algorithms.

πŸ“– Read

via "Threat Post".
πŸ•΄ Data Leaked in Fertility Clinic Ransomware Attack πŸ•΄

Reproductive Biology Associates says the data of 38,000 patients may have been compromised in the April cyberattack.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-24377 β€Ό

The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24372 β€Ό

The WP Hardening ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the $_SERVER['REQUEST_URI'] before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24369 β€Ό

In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Text input fields were not getting sanitized properly. So it was possible to inject malicious content such as img tags, leading to a Stored Cross-Site Scripting issue which is triggered when the form will be edited, for example when an admin reviews it and could lead to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29061 β€Ό

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs.

πŸ“– Read

via "National Vulnerability Database".
❌ Wegmans Exposes Customer Data in Misconfigured Databases ❌

Cleanup in aisle "Oops": The supermarket chain said that it misconfigured two cloud databases, exposing customer data to public scrutiny.

πŸ“– Read

via "Threat Post".
πŸ•΄ Did Companies Fail to Disclose Being Affected by SolarWinds Breach? πŸ•΄

The SEC has sent out letters to some investment firms and publicly listed companies seeking information, Reuters says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2010-0413 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32698 β€Ό

eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20742 β€Ό

Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20733 β€Ό

Improper authorization in handler for custom URL scheme vulnerability in ????????? (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

πŸ“– Read

via "National Vulnerability Database".