πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38149 β€Ό

index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38151 β€Ό

index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37388 β€Ό

A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37381 β€Ό

Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos through CSRF. For example: any student's photo information can be accessed through /gmis/(S([1]))/student/grgl/PotoImageShow/?bh=[2]. Among them, the code in [1] is a random string generated according to the user's login related information. It can protect the user's identity, but it can not effectively prevent unauthorized access. The code in [2] is the student number of any student. The attacker can carry out CSRF attack on the system by modifying [2] without modifying [1].

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38152 β€Ό

index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22295 β€Ό

A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.

πŸ“– Read

via "National Vulnerability Database".
🦿 Phishing continues to target big businesses and exploit COVID-19 fears in Q2 2021 🦿

Spam as a share of global mail traffic rose, and attackers have started to adapt their scams to other languages to reach wider audiences.

πŸ“– Read

via "Tech Republic".
🦿 Amazon Kindle flaws could have allowed attackers to control the device 🦿

Now patched by Amazon, security vulnerabilities found by Check Point would have given attackers access to a Kindle device and its stored data.

πŸ“– Read

via "Tech Republic".
🦿 The most secure browser for transmitting sensitive data is definitely not Chrome 🦿

Jack Wallen addresses the challenging question of which browser is best to use for transmitting encrypted data.

πŸ“– Read

via "Tech Republic".
❌ Angry Affiliate Leaks Conti Ransomware Gang Playbook ❌

The data includes IP addresses for Cobalt Strike C2 servers as well as an archive including numerous tools and training materials for the group, revealing how it performs attacks.

πŸ“– Read

via "Threat Post".
❌ Zoom Settlement: An $85M Business Case for Security Investment   ❌

Zoom’s security lesson over end-to-end encryption shows the costs of playing cybersecurity catchup.

πŸ“– Read

via "Threat Post".
πŸ•΄ Researchers Call for 'CVE' Approach for Cloud Vulnerabilities πŸ•΄

New research suggests isolation among cloud customer accounts may not be a given -- and the researchers behind the findings issue a call to action for cloud security.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-38137 β€Ό

Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor userÒ€ℒs privileges, allowing a user to perform actions not belonging to his role.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37552 β€Ό

In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36707 β€Ό

In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is passed directly to do_system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37541 β€Ό

In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38136 β€Ό

Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the /it-IT/splunkd/__raw/services/get_snapshot HTTP API endpoint. A Γ’β‚¬Λœlow privilegedÒ€ℒ attacker can read any file on the target host.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37547 β€Ό

In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37550 β€Ό

In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37551 β€Ό

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37553 β€Ό

In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.

πŸ“– Read

via "National Vulnerability Database".