πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Chinese threat actors have been compromising telecom networks for years, investigation finds 🦿

Hackers linked to the Chinese government invaded major telecom companies "across Southeast Asia," says reporting firm Cybereason, and the tools they used will sound familiar.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-21565 β€Ό

Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21562 β€Ό

Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT) to provide an untrusted path which can lead to run resources that are not under the applicationÒ€ℒs direct control.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26085 β€Ό

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21563 β€Ό

Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37914 β€Ό

In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21553 β€Ό

Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow the CompAdmin user to elevate privileges and break out of Compliance mode. This is a critical vulnerability and Dell recommends upgrading at the earliest.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37916 β€Ό

Joplin before 2.0.9 allows XSS via button and form in the note body.

πŸ“– Read

via "National Vulnerability Database".
🦿 Connect Ubuntu Linux Desktop 21.04 to an Active Directory domain: Here's how 🦿

Jack Wallen walks you through the steps to join Ubuntu Desktop to Active Directory domains.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-35265 β€Ό

A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37832 β€Ό

A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37833 β€Ό

A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.

πŸ“– Read

via "National Vulnerability Database".
🦿 Olympic-themed passwords put people at risk 🦿

Beyond using "tokyo" and "olympics" as their passwords, people have been turning to names of athletes, such as "kenny," "williams," and "asher," says NordPass.

πŸ“– Read

via "Tech Republic".
❌ β€˜DeadRinger’ Targeted Exchange Servers Long Before Discovery ❌

Cyberespionage campaigns linked to China attacked telecoms via ProxyLogon bugs, stealing call records and maintaining persistence, as far back as 2017.

πŸ“– Read

via "Threat Post".
❌ Raccoon Stealer Bundles Malware, Propagates Via Google SEO ❌

An update to the stealer-as-a-service platform hides in pirated software, pilfers crypto-coins and installs a software dropper for downloads of more malware.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep43: Apple 0-day, pygmy hippos, hive nightmares and Twitter hacker bust [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
⚠ BazarCaller – the malware gang that talks you into infecting yourself ⚠

Calling someone back feels safer than clicking an unknown link... but it isn't! Remind your friends and family.

πŸ“– Read

via "Naked Security".
🦿 DDoS attacks largely target the US and the computers and internet sectors 🦿

DDoS attacks are a nuisance to be sure, but they're also used in a variety of ways that make them a severe threat, says Atlas VPN.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-36157 β€Ό

An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36156 β€Ό

An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31630 β€Ό

Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

πŸ“– Read

via "National Vulnerability Database".