πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-34624 β€Ό

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22555 β€Ό

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36212 β€Ό

app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.

πŸ“– Read

via "National Vulnerability Database".
❌ Fake Kaseya VSA Security Update Drops Cobalt Strike ❌

Threat actors are planting Cobalt Strike backdoors by malspamming a bogus Microsoft update along with a SecurityUpdates.exe.

πŸ“– Read

via "Threat Post".
πŸ•΄ Security 101: The 'PrintNightmare' Flaw πŸ•΄

A closer look at the printer software vulnerability - and what you can do about it.

πŸ“– Read

via "Dark Reading".
🦿 Critical flaws in Windows Print spooler service could allow for remote attacks 🦿

Administrators are urged to apply the latest patches from Microsoft and disable the Windows Print spooler service in domain controllers and systems not used for printing.

πŸ“– Read

via "Tech Republic".
🦿 Critical flaws in Windows Print spooler service could allow for remote attacks 🦿

Administrators are urged to apply the latest patches from Microsoft and disable the Windows Print spooler service in domain controllers and systems not used for printing.

πŸ“– Read

via "Tech Republic".
πŸ›  Zeek 4.0.3 πŸ› 

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. While focusing on network security monitoring, Zeek provides a comprehensive platform for more general network traffic analysis as well. Well grounded in more than 15 years of research, Zeek has successfully bridged the traditional gap between academia and operations since its inception. Today, it is relied upon operationally in particular by many scientific environments for securing their cyber-infrastructure. Zeek's user community includes major universities, research labs, supercomputing centers, and open-science communities. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
❌ Suspected β€˜Dr HeX’ Hacker Busted for 9 Years of Phishing ❌

The unnamed suspect allegedly helped to develop carding and phishing kits with the aim of stealing customers' bank-card data.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-24143 β€Ό

Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20211 β€Ό

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32535 β€Ό

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administratorÒ€ℒs permission and execute arbitrary functions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32514 β€Ό

Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Releases Emergency Patch for 'PrintNightmare' Flaw πŸ•΄

Urges Organizations to immediately apply security update citing exploit activity.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Are Security Attestations a Necessity for SaaS Businesses? πŸ•΄

Are security attestations becoming business imperatives, or are they merely token additions on the list of regulatory requirements?

πŸ“– Read

via "Dark Reading".
🦿 Bitwarden has a new Send feature: Here's how to use it 🦿

This tool will make this productβ€”probably the best password manager on the marketβ€”even better.

πŸ“– Read

via "Tech Republic".
❌ MacOS Targeted in WildPressure APT Malware Campaign ❌

Threat actors enlist compromised WordPress websites in campaign targeting macOS users.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-20416 β€Ό

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 196218.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20415 β€Ό

IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.

πŸ“– Read

via "National Vulnerability Database".
🦿 What to do when 2FA won't allow you into your Linux servers 🦿

If two-factor authentication logins on your Linux servers are giving you fits, Jack Wallen has the solution for you.

πŸ“– Read

via "Tech Republic".
❌ Critical Sage X3 RCE Bug Allows Full System Takeovers ❌

Security vulnerabilities in the ERP platform could allow attackers to tamper with or sabotage victims' business-critical processes and to intercept data.

πŸ“– Read

via "Threat Post".