πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-23697 β€Ό

Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22228 β€Ό

An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql.

πŸ“– Read

via "National Vulnerability Database".
❌ Pro-Trump β€˜Gettr’ Social Platform Hacked On Day One ❌

The newborn platform was inundated by Sonic the Hedgehog-themed porn and had prominent users' profiles defaced. Next, hackers posted its user database online.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-35039 β€Ό

kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20738 β€Ό

WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain sensitive information via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20776 β€Ό

Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary command via telnet.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft Releases Emergency Patch for PrintNightmare Bugs ❌

The fix doesn’t cover the entire problem nor all affected systems however, so the company also is offering workarounds and plans to release further remedies at a later date.

πŸ“– Read

via "Threat Post".
❌ Cloud Cryptomining Swindle in Google Play Rakes in Cash ❌

At least 25 apps have lured in tens of thousands of victims with the promise of helping them cash in on the cryptomining craze.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-22227 β€Ό

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22230 β€Ό

Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.

πŸ“– Read

via "National Vulnerability Database".
⚠ PrintNightmare official patch is out – update now! ⚠

Patch now! This security hole could allow almost anyone to take over your whole network from almost any account on almost any computer.

πŸ“– Read

via "Naked Security".
πŸ•΄ Autonomous Security Is Essential if the Edge Is to Scale Properly πŸ•΄

Service demands at the network edge mean customers need to get cost, performance, and security right.

πŸ“– Read

via "Dark Reading".
🦿 Microsoft rolls out emergency patch for critical PrintNightmare flaw 🦿

Fixing a serious security hole in the Windows Print spooler service, the patch is available for almost all versions of Windows, even Windows 7.

πŸ“– Read

via "Tech Republic".
❌ Why I Love (Breaking Into) Your Security Appliances ❌

David "moose" Wolpoff, CTO at Randori, discusses security appliances and VPNs and how attackers only have to "pick one lock" to invade an enterprise through them.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-34623 β€Ό

A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34624 β€Ό

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22555 β€Ό

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36212 β€Ό

app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.

πŸ“– Read

via "National Vulnerability Database".
❌ Fake Kaseya VSA Security Update Drops Cobalt Strike ❌

Threat actors are planting Cobalt Strike backdoors by malspamming a bogus Microsoft update along with a SecurityUpdates.exe.

πŸ“– Read

via "Threat Post".
πŸ•΄ Security 101: The 'PrintNightmare' Flaw πŸ•΄

A closer look at the printer software vulnerability - and what you can do about it.

πŸ“– Read

via "Dark Reading".
🦿 Critical flaws in Windows Print spooler service could allow for remote attacks 🦿

Administrators are urged to apply the latest patches from Microsoft and disable the Windows Print spooler service in domain controllers and systems not used for printing.

πŸ“– Read

via "Tech Republic".