πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Microsoft fixes Print Spooler bugs with August Patch Tuesday rollout 🦿

The fix, though, means that only administrators will be able to install print drivers on Windows PCs.

πŸ“– Read

via "Tech Republic".
🦿 When 2FA on your Linux servers won't let you in, try this fix 🦿

When your Linux servers are giving you fits, Jack Wallen has the solution for you.

πŸ“– Read

via "Tech Republic".
❌ Ransomware Payments Explode Amid β€˜Quadruple Extortion’ ❌

Unit 42 puts the average payout at over half a million, while Barracuda has tracked a 64 percent year over year spike in the number of attacks.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-27792 β€Ό

The command Ò€œipfilterҀ� in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27794 β€Ό

A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35955 β€Ό

Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20314 β€Ό

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20981 β€Ό

A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38087 β€Ό

Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20975 β€Ό

In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20979 β€Ό

An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20977 β€Ό

A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27793 β€Ό

ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the switch.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38086 β€Ό

Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37841 β€Ό

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27791 β€Ό

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38597 β€Ό

wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27790 β€Ό

The command Ò€œipfilterҀ� in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38088 β€Ό

Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.

πŸ“– Read

via "National Vulnerability Database".
🦿 For sale: Access to your company network. Price: Less than you'd think 🦿

Access to secured networks is regularly sold on the Dark Web and 45% of those sales are less than $1,000.

πŸ“– Read

via "Tech Republic".
❌ AdLoad Malware 2021 Samples Skate Past Apple XProtect ❌

A crush of new attacks using the well-known adware involves at least 150 updated samples, many of which aren't recognized by Apple's built-in security controls.

πŸ“– Read

via "Threat Post".