πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38593 β€Ό

Qt 5.0.0 through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37222 β€Ό

Parsers in the open source project RCDCAP before 1.0.5 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via specially crafted packets.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24576 β€Ό

Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft Warns: Another Unpatched PrintNightmare Zero-Day ❌

The out-of-band warning pairs with a working proof-of-concept exploit for the issue, circulating since mid-July.

πŸ“– Read

via "Threat Post".
❌ QR Code Scammers Get Creative with Bitcoin ATMs ❌

Threat actors are targeting everyone from job hunters to Bitcoin traders to college students wanting a break on their student loans, by exploiting the popular technology's trust relationship with users.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep45: Routers attacked, hacking tool hacked, and betrayers betrayed [Podcast] ⚠

Latest episode - listen now! (And learn about the Navajo Nation's selfless cryptographic contribution to America.)

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-28165 β€Ό

The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.

πŸ“– Read

via "National Vulnerability Database".
🦿 Microsoft fixes Print Spooler bugs with August Patch Tuesday rollout 🦿

The fix, though, means that only administrators will be able to install print drivers on Windows PCs.

πŸ“– Read

via "Tech Republic".
🦿 When 2FA on your Linux servers won't let you in, try this fix 🦿

When your Linux servers are giving you fits, Jack Wallen has the solution for you.

πŸ“– Read

via "Tech Republic".
❌ Ransomware Payments Explode Amid β€˜Quadruple Extortion’ ❌

Unit 42 puts the average payout at over half a million, while Barracuda has tracked a 64 percent year over year spike in the number of attacks.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-27792 β€Ό

The command Ò€œipfilterҀ� in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27794 β€Ό

A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35955 β€Ό

Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20314 β€Ό

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20981 β€Ό

A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38087 β€Ό

Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20975 β€Ό

In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20979 β€Ό

An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20977 β€Ό

A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27793 β€Ό

ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the switch.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38086 β€Ό

Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.

πŸ“– Read

via "National Vulnerability Database".