β Critical VMware Carbon Black Bug Allows Authentication Bypass β
π Read
via "Threat Post".
The 9.4-rated bug in AppC could give attackers admin rights, no authentication required, letting them attack anything from PoS to industrial control systems.π Read
via "Threat Post".
Threat Post
Critical VMware Carbon Black Bug Allows Authentication Bypass
The 9.4-rated bug in AppC could give attackers admin rights, no authentication required, letting them attack anything from PoS to industrial control systems.
βΌ CVE-2021-24000 βΌ
π Read
via "National Vulnerability Database".
A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as <input type="file">) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not intend to. This vulnerability affects Firefox < 88.π Read
via "National Vulnerability Database".
βΌ CVE-2021-29963 βΌ
π Read
via "National Vulnerability Database".
Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.π Read
via "National Vulnerability Database".
βΌ CVE-2021-29953 βΌ
π Read
via "National Vulnerability Database".
A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resulting in a Universal Cross-Site Scripting vulnerability. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected. Further details are being temporarily withheld to allow users an opportunity to update.*. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.π Read
via "National Vulnerability Database".
βΌ CVE-2020-21787 βΌ
π Read
via "National Vulnerability Database".
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.π Read
via "National Vulnerability Database".
π΄ Boardroom Perspectives on Cybersecurity: What It Means for You π΄
π Read
via "Dark Reading".
Because board members are paying close attention to security, security leaders must be able to respond to and alleviate their concerns with data.π Read
via "Dark Reading".
βΌ CVE-2020-18664 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.π Read
via "National Vulnerability Database".
βΌ CVE-2020-21783 βΌ
π Read
via "National Vulnerability Database".
In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32708 βΌ
π Read
via "National Vulnerability Database".
Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely. The conditions are: A user is allowed to supply the path or filename of an uploaded file, the supplied path or filename is not checked against unicode chars, the supplied pathname checked against an extension deny-list, not an allow-list, the supplied path or filename contains a unicode whitespace char in the extension, the uploaded file is stored in a directory that allows PHP code to be executed. Given these conditions are met a user can upload and execute arbitrary code on the system under attack. The unicode whitespace removal has been replaced with a rejection (exception). For 1.x users, upgrade to 1.1.4. For 2.x users, upgrade to 2.1.1.π Read
via "National Vulnerability Database".
π΄ Preinstalled Firmware Updater Puts 128 Dell Models at Risk π΄
π Read
via "Dark Reading".
A feature of the computer maker's update utility does not correctly handle certificates, leaving systems open to firmware-level compromises.π Read
via "Dark Reading".
Dark Reading
Preinstalled Firmware Updater Puts 128 Dell Models at Risk
A feature of the computer maker's update utility does not correctly handle certificates, leaving systems open to firmware-level compromises.
π¦Ώ How to easily join an AlmaLinux server to an Active Directory Domain with Cockpit π¦Ώ
π Read
via "Tech Republic".
Jack Wallen shows you just how easy it is to join an existing AlmaLinux server to an Active Directory domain via a web-based GUI.π Read
via "Tech Republic".
TechRepublic
How to easily join an AlmaLinux server to an Active Directory Domain with Cockpit
Jack Wallen shows you just how easy it is to join an existing AlmaLinux server to an Active Directory domain via a web-based GUI.
π΄ Tulsa Officials Warn Ransomware Attackers Leaked City Files π΄
π Read
via "Dark Reading".
The group behind the May 2021 attack has shared more than 18,000 files via the Dark Web, mostly internal department files and police citations.π Read
via "Dark Reading".
Dark Reading
Tulsa Officials Warn Ransomware Attackers Leaked City Files
The group behind the May 2021 attack has shared more than 18,000 files via the Dark Web, mostly internal department files and police citations.
β Oh FCUK! Fashion Label, Medical Diagnostics Firm Latest REvil Victims β
π Read
via "Threat Post".
The infamous ransomware group hit two big-name companies within hours of each other. π Read
via "Threat Post".
Threat Post
Oh FCUK! Fashion Label, Medical Diagnostics Firm Latest REvil Victims
The infamous ransomware group hit two big-name companies within hours of each other.
βΌ CVE-2021-32491 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.π Read
via "National Vulnerability Database".
βΌ CVE-2020-4945 βΌ
π Read
via "National Vulnerability Database".
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.π Read
via "National Vulnerability Database".
π First CCPA Rights Requests Deadline Looms π
π Read
via "".
Organizations that comply with the CCPA should be aware of an upcoming public reporting requirement deadline, one of the first deadlines under the relatively new law.π Read
via "".
Digital Guardian
First CCPA Rights Requests Deadline Looms
Organizations that comply with the CCPA should be aware of an upcoming public reporting requirement deadline, one of the first deadlines under the relatively new law.
π΄ 74% of Q1 Malware Was Undetectable Via Signature-Based Tools π΄
π Read
via "Dark Reading".
Attackers have improved on tweaking old malware to continue sneaking it past traditional threat detection controls, researchers report.π Read
via "Dark Reading".
Dark Reading
74% of Q1 Malware Was Undetectable Via Signature-Based Tools
Attackers have improved on tweaking old malware to continue sneaking it past traditional threat detection controls, researchers report.
βΌ CVE-2021-32716 βΌ
π Read
via "National Vulnerability Database".
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32711 βΌ
π Read
via "National Vulnerability Database".
Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by this change. We recommend to update to the current version 6.3.5.1. You can get the update to 6.3.5.1 regularly via the Auto-Updater or directly via the download overview. https://www.shopware.com/en/download/#shopware-6 The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by this change. Please check your plugins if you have it in use. Detailed technical information can be found in the upgrade information. https://github.com/shopware/platform/blob/v6.3.5.1/UPGRADE-6.3.md#6351 ### Workarounds For older versions of 6.1 and 6.2, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version. https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659 ### For more information https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-02-2021π Read
via "National Vulnerability Database".
β Spam Downpour Drips New IcedID Banking Trojan Variant β
π Read
via "Threat Post".
The primarily IcedID-flavored banking trojan spam campaigns were coming in at a fever pitch: Spikes hit more than 100 detections a day.π Read
via "Threat Post".
Threat Post
Spam Downpour Drips New IcedID Banking Trojan Variant
The primarily IcedID-flavored banking trojan spam campaigns were coming in at a fever pitch: Spikes hit more than 100 detections a day.
β British tourists charged Β£1000s for pier visits in billing blunder β
π Read
via "Naked Security".
That's a LOT of money just to visit a seaside pier!π Read
via "Naked Security".
Naked Security
British tourists charged Β£1000s for pier visits in billing blunder
Thatβs a LOT of money just to visit a seaside pier!