πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-37841 β€Ό

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27791 β€Ό

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38597 β€Ό

wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27790 β€Ό

The command Ò€œipfilterҀ� in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38088 β€Ό

Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.

πŸ“– Read

via "National Vulnerability Database".
🦿 For sale: Access to your company network. Price: Less than you'd think 🦿

Access to secured networks is regularly sold on the Dark Web and 45% of those sales are less than $1,000.

πŸ“– Read

via "Tech Republic".
❌ AdLoad Malware 2021 Samples Skate Past Apple XProtect ❌

A crush of new attacks using the well-known adware involves at least 150 updated samples, many of which aren't recognized by Apple's built-in security controls.

πŸ“– Read

via "Threat Post".
πŸ” Progress Being Made Fortifying US Cyber Defenses πŸ”

Nearly 75 percent of the Cyberspace Solarium Commission's federal recommendations have been implemented or are on track to being implemented.

πŸ“– Read

via "".
β€Ό CVE-2020-18445 β€Ό

Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20509 β€Ό

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32808 β€Ό

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38606 β€Ό

reNgine through 0.5 relies on a predictable directory name.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38291 β€Ό

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38604 β€Ό

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32809 β€Ό

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38599 β€Ό

WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18446 β€Ό

Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.

πŸ“– Read

via "National Vulnerability Database".
❌ Black Hat: Novel DNS Hack Spills Confidential Corp Data ❌

Threatpost interviews Wiz CTO about a vulnerability recently patched by Amazon Route53's DNS service and Google Cloud DNS.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-34534 β€Ό

Windows MSHTML Platform Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36938 β€Ό

Windows Cryptographic Primitives Library Information Disclosure Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36949 β€Ό

Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability

πŸ“– Read

via "National Vulnerability Database".