πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Attackers Exploited 4 Zero-Day Flaws in Chrome, Safari & IE πŸ•΄

At least two government-backed actors -- including one Russian group -- used the now-patched flaws in separate campaigns, Google says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-23707 β€Ό

A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23705 β€Ό

A global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36758 β€Ό

1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets Automation access tokens can create tokens that have access beyond what the user is authorized to access, but limited to the existing authorizations of the Secret Automation the token is created in.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft: New Unpatched Bug in Windows Print Spooler            ❌

Another vulnerability separate from PrintNightmare allows for local elevation of privilege and system takeover.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-21802 β€Ό

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21818 β€Ό

A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of requests to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21820 β€Ό

A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21801 β€Ό

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How to Attract More Computer Science Grads to the Cybersecurity Field πŸ•΄

With 465,000 cybersecurity job openings in the United States, why is recruiting so difficult? A recent college graduate offers his take.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-1422 β€Ό

A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle position to cause an unexpected reload of the device that results in a denial of service (DoS) condition. The vulnerability is due to a logic error in how the software cryptography module handles specific types of decryption errors. An attacker could exploit this vulnerability by sending malicious packets over an established IPsec connection. A successful exploit could cause the device to crash, forcing it to reload. Important: Successful exploitation of this vulnerability would not cause a compromise of any encrypted data. Note: This vulnerability affects only Cisco ASA Software Release 9.16.1 and Cisco FTD Software Release 7.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28114 β€Ό

Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 4 Future Integrated Circuit Threats to Watch πŸ•΄

Threats to the supply chains for ICs and other computer components are poised to wreak even more havoc on organizations.

πŸ“– Read

via "Dark Reading".
πŸ” Friday Five 7/16 πŸ”

iOS zero days, the state of U.S. chipmaking, and the disruption of a phishing ring - catch up on all of the week's infosec news with the Friday Five!

πŸ“– Read

via "".
⚠ Want to earn $10 million? Snitch on a cybercrook! ⚠

Will going after the big guns help to discourage and disrupt the rest of the cybercrime ecosystem? Have your say...

πŸ“– Read

via "Naked Security".
❌ Windows 0-Days Used Against Dissidents in Israeli Broker’s Spyware ❌

Candiru, aka Sourgum, allegedly sells the DevilsTongue surveillance malware to governments around the world.

πŸ“– Read

via "Threat Post".
⚠ More PrintNightmare: β€œWe TOLD you not to turn the Print Spooler back on!” ⚠

The PrintNightmare continues. So does our advice, even though it stops your printer working.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-3649 β€Ό

chatwoot is vulnerable to Inefficient Regular Expression Complexity

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28054 β€Ό

An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration > Hosts" allows remote authenticated users to inject arbitrary web script or HTML via the Alias parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical Juniper Bug Allows DoS, RCE Against Carrier Networks ❌

Telecom providers, including wireless carriers, are at risk of disruption of network service if the bug in SBR Carrier is exploited.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-4821 β€Ό

IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Force ID: 189834

πŸ“– Read

via "National Vulnerability Database".