πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-25652 β€Ό

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects versions 8.0.0.0 through 8.1.3.1 of AVPU.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25655 β€Ό

A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).

πŸ“– Read

via "National Vulnerability Database".
❌ 30M Dell Devices at Risk for Remote BIOS Attacks, RCE ❌

Four separate security bugs would give attackers almost complete control and persistence over targeted devices, thanks to a faulty update mechanism.

πŸ“– Read

via "Threat Post".
❌ Atlassian Bugs Could Have Led to 1-Click Takeover ❌

A supply-chain attack could have siphoned sensitive information out of Jira, such as security issues on Atlassian cloud, Bitbucket and on-prem products.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-21737 β€Ό

A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10 B860H V5.0, V83011303.0010, V83011303.0016

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ rMTD: A Deception Method That Throws Attackers Off Their Game πŸ•΄

Through a variety of techniques, rotational Moving Target Defense makes existing OS and app vulnerabilities exponentially difficult to exploit. Here's how.

πŸ“– Read

via "Dark Reading".
❌ Tulsa’s Police-Citation Data Leaked by Conti Gang ❌

A May 6 ransomware attack caused disruption across several of the municipality’s online services and websites.

πŸ“– Read

via "Threat Post".
πŸ•΄ John McAfee, Creator of McAfee Antivirus Software, Dead at 75 πŸ•΄

McAfee, who was being held in a Spanish jail on US tax-evasion charges, had learned on Monday he would be extradited to the US.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Storms & Silver Linings: Avoiding the Dangers of Cloud Migration πŸ•΄

We hear a lot about the sunlit uplands of cloud-powered business, but what about the risks of making information available across the organization?

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-26585 β€Ό

A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28097 β€Ό

The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85.

πŸ“– Read

via "National Vulnerability Database".
🦿 Remote Access Trojan now targeting schools with ransomware 🦿

Dubbed ChaChi by researchers at BlackBerry, the RAT has recently shifted its focus from government agencies to schools in the US.

πŸ“– Read

via "Tech Republic".
⚠ S3 Ep38: Clop busts, destructive Linux hacking, and rooted bicycles [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
❌ Critical VMware Carbon Black Bug Allows Authentication Bypass ❌

The 9.4-rated bug in AppC could give attackers admin rights, no authentication required, letting them attack anything from PoS to industrial control systems.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-24000 β€Ό

A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as &lt;input type="file"&gt;) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not intend to. This vulnerability affects Firefox < 88.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29963 β€Ό

Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29953 β€Ό

A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resulting in a Universal Cross-Site Scripting vulnerability. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected. Further details are being temporarily withheld to allow users an opportunity to update.*. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21787 β€Ό

CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Boardroom Perspectives on Cybersecurity: What It Means for You πŸ•΄

Because board members are paying close attention to security, security leaders must be able to respond to and alleviate their concerns with data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-18664 β€Ό

Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21783 β€Ό

In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter.

πŸ“– Read

via "National Vulnerability Database".