πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-22523 β€Ό

XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35521 β€Ό

A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows remote authenticated attackers to achieve denial of services and information disclosure via TCP/IP packets.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22522 β€Ό

Reflected Cross-Site Scripting vulnerability in Micro Focus Verastream Host Integrator, affecting version version 7.8 Update 1 and earlier versions. The vulnerability could allow disclosure of confidential data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30110 β€Ό

dttray.exe in Greyware Automation Products Inc Domain Time II before 5.2.b.20210331 allows remote attackers to execute arbitrary code via a URL to a malicious update in a spoofed response to the UDP query used to check for updates.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35520 β€Ό

A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authenticated attackers to achieve code execution, denial of services, and information disclosure via serial ports.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30049 β€Ό

SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30486 β€Ό

SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or group1), or AssetManagementSummary.jsp (GET group1).

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep42: Viruses, Nightmares, patches, rewards and scammers [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
🦿 The ransomware risk management calculus is changing for OT, ICS and critical infrastructure 🦿

Paralysis is the worst possible state for businesses to find themselves in when faced with the threat, says Claroty's CPO.

πŸ“– Read

via "Tech Republic".
🦿 How cyberattacks exploit known security vulnerabilities 🦿

Knowing that many organizations fail to patch known flaws, attackers continually scan for security holes that they can exploit, says Barracuda.

πŸ“– Read

via "Tech Republic".
🦿 Systemd can't seem to catch a break: New vulnerability found 🦿

A dangerous vulnerability was found in the Linux systemd stack. Find out what it is and how to upgrade your Linux distributions.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-22001 β€Ό

In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type Ò€œoauth 1.0Ҁ� was sent to UAA server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29143 β€Ό

A remote execution of arbitrary commands vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): Aruba AOS-CX firmware: 10.04.xxxx - versions prior to 10.04.3070, 10.05.xxxx - versions prior to 10.05.0070, 10.06.xxxx - versions prior to 10.06.0110, 10.07.xxxx - versions prior to 10.07.0001. Aruba has released upgrades for Aruba AOS-CX devices that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34431 β€Ό

In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29149 β€Ό

A local bypass security restrictions vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): Aruba AOS-CX firmware: 10.04.xxxx - versions prior to 10.04.3070, 10.05.xxxx - versions prior to 10.05.0070, 10.06.xxxx - versions prior to 10.06.0110, 10.07.xxxx - versions prior to 10.07.0001. Aruba has released upgrades for Aruba AOS-CX devices that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29148 β€Ό

A local cross-site scripting (XSS) vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): Aruba AOS-CX firmware: 10.04.xxxx - versions prior to 10.04.3070, 10.05.xxxx - versions prior to 10.05.0070, 10.06.xxxx - versions prior to 10.06.0110, 10.07.xxxx - versions prior to 10.07.0001. Aruba has released upgrades for Aruba AOS-CX devices that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
❌ Apple Issues Urgent iPhone Updates; None for Pegasus Zero-Day ❌

Update now: The ream of bugs includes some remotely exploitable code execution flaws. Still to come: a fix for what makes iPhones easy prey for Pegasus spyware.

πŸ“– Read

via "Threat Post".
πŸ•΄ 7 Hot Cyber Threat Trends to Expect at Black Hat πŸ•΄

A sneak peek of some of the main themes at Black Hat USA next month.

πŸ“– Read

via "Dark Reading".
πŸ” An Interview with Adam Burns, Manager of Cybersecurity Analysts at Digital Guardian Part II πŸ”

In part two of our Q&A with Adam Burns, we discuss how to expand the security talent pool, the potential impact of automation on infosec, and the biggest challenge facing the industry.

πŸ“– Read

via "".
🦿 Scammers offer streaming services, giveaways and a fake cyber currency to cash in on the Olympic Games 🦿

Kaspersky's analysis found that cybercriminals are getting extra creative with the latest campaigns designed to harvest credentials.

πŸ“– Read

via "Tech Republic".
❌ Industrial Networks Exposed Through Cloud-Based Operational Tech ❌

Critical ICS vulnerabilities can be exploited through leading cloud-management platforms.

πŸ“– Read

via "Threat Post".