πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-36382 β€Ό

Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18979 β€Ό

Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via theX-forwarded-for Header parameter.

πŸ“– Read

via "National Vulnerability Database".
⚠ Where do all those cybercrime payments go? ⚠

Yes, the headline is a rhetorical question. But sometimes we get literal answers, and they're well worth remembering.

πŸ“– Read

via "Naked Security".
🦿 The most dangerous messaging apps on Android 🦿

Messaging apps are becoming some of the most popular smartphone programs in the world, and that means more attempts to phish their users, Kaspersky finds.

πŸ“– Read

via "Tech Republic".
⚠ Don’t get tricked by this crashtastic iPhone Wi-Fi hack! ⚠

Learn how the trick works so that you can avoid it in case someone thinks it's a joke to catch you out.

πŸ“– Read

via "Naked Security".
❌ Critical RCE Vulnerability in ForgeRock OpenAM Under Active Attack ❌

The attacks are enabled by an unpatched security vulnerability in ForgeRock's Access Management, a popular platform that front-ends web apps and remote-access setups.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-32703 β€Ό

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20414 β€Ό

IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36381 β€Ό

In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_error= on the login screen of the Web application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29803 β€Ό

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204164.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Confirms Acquisition of RiskIQ πŸ•΄

RiskIQ's technology helps businesses assess their security across the Microsoft cloud, Amazon Web Services, other clouds, and on-premises.

πŸ“– Read

via "Dark Reading".
πŸ” European Authorities Bust Phishing Ring πŸ”

The group, which was based in Romania, reportedly conned online consumers out of $2 million.

πŸ“– Read

via "".
β€Ό CVE-2021-32707 β€Ό

Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by default, render images in emails to not leak the read state. The privacy filter failed to filter images with a `background-image` CSS attribute. Note that the images were still passed through the Nextcloud image proxy, and thus there was no IP leakage. The issue was patched in version 1.9.6 and 1.10.0. No workarounds are known to exist.

πŸ“– Read

via "National Vulnerability Database".
❌ WordPress File Management Plugin Riddled with Critical Bugs ❌

The bugs allow a range of attacks on websites, including deleting blog pages and remote code execution.

πŸ“– Read

via "Threat Post".
πŸ•΄ SolarWinds Discloses Zero-Day Under Active Attack πŸ•΄

The company confirms this is a new vulnerability that is not related to the supply chain attack discovered in December 2020.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-24426 β€Ό

The Backup by 10Web ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Backup and Restore Plugin WordPress plugin through 1.0.20 does not sanitise or escape the tab parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19907 β€Ό

A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24421 β€Ό

The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32747 β€Ό

Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed to unauthorized users exists between versions 2.0.0 and 2.8.2. Custom variables are user-defined keys and values on configuration objects in Icinga 2. These are commonly used to reference secrets in other configurations such as check commands to be able to authenticate with a service being checked. Icinga Web 2 displays these custom variables to logged in users with access to said hosts or services. In order to protect the secrets from being visible to anyone, it's possible to setup protection rules and blacklists in a user's role. Protection rules result in `***` being shown instead of the original value, the key will remain. Backlists will hide a custom variable entirely from the user. Besides using the UI, custom variables can also be accessed differently by using an undocumented URL parameter. By adding a parameter to the affected routes, Icinga Web 2 will show these columns additionally in the respective list. This parameter is also respected when exporting to JSON or CSV. Protection rules and blacklists however have no effect in this case. Custom variables are shown as-is in the result. The issue has been fixed in the 2.9.0, 2.8.3, and 2.7.5 releases. As a workaround, one may set up a restriction to hide hosts and services with the custom variable in question.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32741 β€Ό

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
🦿 Vulnerability in Schneider Electric PLCs allows for undetectable remote takeover 🦿

Dubbed Modipwn, the vulnerability affects a wide variety of Modicon programmable logic controllers used in manufacturing, utilities, automation and other roles.

πŸ“– Read

via "Tech Republic".