πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38086 β€Ό

Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37841 β€Ό

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27791 β€Ό

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38597 β€Ό

wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27790 β€Ό

The command Ò€œipfilterҀ� in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38088 β€Ό

Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.

πŸ“– Read

via "National Vulnerability Database".
🦿 For sale: Access to your company network. Price: Less than you'd think 🦿

Access to secured networks is regularly sold on the Dark Web and 45% of those sales are less than $1,000.

πŸ“– Read

via "Tech Republic".
❌ AdLoad Malware 2021 Samples Skate Past Apple XProtect ❌

A crush of new attacks using the well-known adware involves at least 150 updated samples, many of which aren't recognized by Apple's built-in security controls.

πŸ“– Read

via "Threat Post".
πŸ” Progress Being Made Fortifying US Cyber Defenses πŸ”

Nearly 75 percent of the Cyberspace Solarium Commission's federal recommendations have been implemented or are on track to being implemented.

πŸ“– Read

via "".
β€Ό CVE-2020-18445 β€Ό

Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20509 β€Ό

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32808 β€Ό

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38606 β€Ό

reNgine through 0.5 relies on a predictable directory name.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38291 β€Ό

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38604 β€Ό

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32809 β€Ό

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38599 β€Ό

WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18446 β€Ό

Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.

πŸ“– Read

via "National Vulnerability Database".
❌ Black Hat: Novel DNS Hack Spills Confidential Corp Data ❌

Threatpost interviews Wiz CTO about a vulnerability recently patched by Amazon Route53's DNS service and Google Cloud DNS.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-34534 β€Ό

Windows MSHTML Platform Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36938 β€Ό

Windows Cryptographic Primitives Library Information Disclosure Vulnerability

πŸ“– Read

via "National Vulnerability Database".