πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-26085 β€Ό

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21563 β€Ό

Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37914 β€Ό

In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21553 β€Ό

Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow the CompAdmin user to elevate privileges and break out of Compliance mode. This is a critical vulnerability and Dell recommends upgrading at the earliest.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37916 β€Ό

Joplin before 2.0.9 allows XSS via button and form in the note body.

πŸ“– Read

via "National Vulnerability Database".
🦿 Connect Ubuntu Linux Desktop 21.04 to an Active Directory domain: Here's how 🦿

Jack Wallen walks you through the steps to join Ubuntu Desktop to Active Directory domains.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-35265 β€Ό

A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37832 β€Ό

A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37833 β€Ό

A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.

πŸ“– Read

via "National Vulnerability Database".
🦿 Olympic-themed passwords put people at risk 🦿

Beyond using "tokyo" and "olympics" as their passwords, people have been turning to names of athletes, such as "kenny," "williams," and "asher," says NordPass.

πŸ“– Read

via "Tech Republic".
❌ β€˜DeadRinger’ Targeted Exchange Servers Long Before Discovery ❌

Cyberespionage campaigns linked to China attacked telecoms via ProxyLogon bugs, stealing call records and maintaining persistence, as far back as 2017.

πŸ“– Read

via "Threat Post".
❌ Raccoon Stealer Bundles Malware, Propagates Via Google SEO ❌

An update to the stealer-as-a-service platform hides in pirated software, pilfers crypto-coins and installs a software dropper for downloads of more malware.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep43: Apple 0-day, pygmy hippos, hive nightmares and Twitter hacker bust [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
⚠ BazarCaller – the malware gang that talks you into infecting yourself ⚠

Calling someone back feels safer than clicking an unknown link... but it isn't! Remind your friends and family.

πŸ“– Read

via "Naked Security".
🦿 DDoS attacks largely target the US and the computers and internet sectors 🦿

DDoS attacks are a nuisance to be sure, but they're also used in a variety of ways that make them a severe threat, says Atlas VPN.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-36157 β€Ό

An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36156 β€Ό

An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31630 β€Ό

Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36379 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27952 β€Ό

Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22400 β€Ό

Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The app can modify specific parameters, causing the system to crash. Affected product include:OxfordS-AN00A 10.0.1.10(C00E10R1P1),10.0.1.105(C00E103R3P3),10.0.1.115(C00E110R3P3),10.0.1.123(C00E121R3P3),10.0.1.135(C00E130R3P3),10.0.1.135(C00E130R4P1),10.0.1.152(C00E140R4P1),10.0.1.160(C00E160R4P1),10.0.1.167(C00E166R4P1),10.0.1.173(C00E172R5P1),10.0.1.178(C00E175R5P1) and 10.1.0.202(C00E79R5P1).

πŸ“– Read

via "National Vulnerability Database".