πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-23209 β€Ό

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23205 β€Ό

A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted a payload entered into the "Site Name" field under the "Site Settings" module.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ GitHub Unveils AI Tool to Speed Development, but Beware Insecure Code πŸ•΄

The company has created an AI system, dubbed Copilot, to offer code suggestions to developers, but warns that any code produced should be tested for defects and vulnerabilities.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-26920 β€Ό

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid directly, since Druid also provides the Local InputSource, which allows the same level of access. But it is problematic when users interact with Druid indirectly through an application that allows users to specify the HTTP InputSource, but not the Local InputSource. In this case, users could bypass the application-level restriction by passing a file URL to the HTTP InputSource.

πŸ“– Read

via "National Vulnerability Database".
❌ CISA Offers New Mitigation for PrintNightmare Bug ❌

CERT urges administrators to disable the Windows Print spooler service in Domain Controllers and systems that don’t print, while Microsoft attempts to clarify RCE flaw with a new CVE assignment.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-27455 β€Ό

Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35029 β€Ό

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.

πŸ“– Read

via "National Vulnerability Database".
⚠ US email hacker gets his β€œcomputer trespass” conviction reversed ⚠

Court says that we need to "avoid a construction that makes some language mere surplusage."

πŸ“– Read

via "Naked Security".
🦿 Container security: How to get the most out of best practices 🦿

Containers are complex virtual entities that provide proven benefits to the business but also require strong security guidelines. Learn how to get the most out of container security best practices.

πŸ“– Read

via "Tech Republic".
πŸ•΄ WFH: A Smart Time to Revisit Employee Use of Social Media πŸ•΄

Employers have their hands full when it comes to monitoring online activities that could hurt the brand or violate the organization's core values.

πŸ“– Read

via "Dark Reading".
πŸ” Friday Five 7/2 πŸ”

Ransomware venture capital, VPN shutdowns, and the latest from Fancy Bear - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "".
β€Ό CVE-2021-36130 β€Ό

An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data fields. The attack could easily propagate across many pages for many users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36132 β€Ό

An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3606 β€Ό

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 5 Mistakes That Impact a Security Team's Success πŸ•΄

The way we work and treat each other go a long way in improving our organizations' security posture.

πŸ“– Read

via "Dark Reading".
❌ TrickBot Spruces Up Its Banking Trojan Module ❌

After focusing almost exclusively on delivering ransomware for the past year, the code changes could indicate that TrickBot is getting back into the bank-fraud game.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-27950 β€Ό

A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to execute arbitrary SQL commands via the id parameter to mesdocs.ajax.php in azurWebEngine/eShop. By default, the query is executed as DBA.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32735 β€Ό

Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attacks. Malicious authenticated Panel users can escalate their privileges if they get access to the Panel session of an admin user. Visitors without Panel access can use the attack vector if the site allows changing site data from a frontend form. Kirby 3.5.7 patches the vulnerability. As a partial workaround, site administrators can protect against attacks from visitors without Panel access by validating or sanitizing provided data from the frontend form.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Suricata IDPE 6.0.3 πŸ› 

Suricata is a network intrusion detection and prevention engine developed by the Open Information Security Foundation and its supporting vendors. The engine is multi-threaded and has native IPv6 support. It's capable of loading existing Snort rules and signatures and supports the Barnyard and Barnyard2 tools.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ SOC Investment Improves Detection and Response Times, Data Shows πŸ•΄

A survey of IT and security pros finds many are confident in their ability to detect security incidents in near-real time or within minutes.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Issues New CVE for 'PrintNightmare' Flaw πŸ•΄

Company says remote code execution issue in all Windows versions is different from one in Windows Print Spooler that it had patched last month, though both affect same function.

πŸ“– Read

via "Dark Reading".