πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-39156 β€Ό

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exploitable vulnerability where an HTTP request with `#fragment` in the path may bypass IstioΓƒΒ’Γ’β€šΒ¬Γ’β€žΒ’s URI path based authorization policies. Patches are available in Istio 1.11.1, Istio 1.10.4 and Istio 1.9.8. As a work around a Lua filter may be written to normalize the path.

πŸ“– Read

via "National Vulnerability Database".
❌ California Man Hacked iCloud Accounts to Steal Nude Photos ❌

Hao Kou Chi pleaded guilty to four felonies in a hacker-for-hire scam that used socially engineered emails to trick people out of their credentials.

πŸ“– Read

via "Threat Post".
🦿 How safe is a quantum-safe virtual private network? 🦿

Verizon aims to find out by testing the technology, which is geared at enhancing encryption methods using session key exchange security mechanisms, the carrier said.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-33884 β€Ό

An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote attackers to upload any files to the /tmp directory of the device through the webpage API. This can result in critical files being overwritten.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33605 β€Ό

Improper check in CheckboxGroup in com.vaadin:vaadin-checkbox-flow versions 1.2.0 prior to 2.0.0 (Vaadin 12.0.0 prior to 14.0.0), 2.0.0 prior to 3.0.0 (Vaadin 14.0.0 prior to 14.5.0), 3.0.0 through 4.0.1 (Vaadin 15.0.0 through 17.0.11), 14.5.0 through 14.6.7 (Vaadin 14.5.0 through 14.6.7), and 18.0.0 through 20.0.5 (Vaadin 18.0.0 through 20.0.5) allows attackers to modify the value of a disabled Checkbox inside enabled CheckboxGroup component via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33882 β€Ό

A Missing Authentication for Critical Function vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to reconfigure the device from an unknown source because of lack of authentication on proprietary networking commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33885 β€Ό

An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to send the device malicious data that will be used in place of the correct data. This results in full system command access and execution because of the lack of cryptographic signatures on critical data sets.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33883 β€Ό

A Cleartext Transmission of Sensitive Information vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to obtain sensitive information by snooping on the network traffic. The exposed data includes critical values for a pump's internal configuration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33886 β€Ό

An improper sanitization of input vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to gain user-level command-line access by passing a raw external string straight through to printf statements. The attacker is required to be on the same network as the device.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  I2P 1.5.0 πŸ› 

I2P is an anonymizing network, offering a simple layer that identity-sensitive applications can use to securely communicate. All data is wrapped with several layers of encryption, and the network is both distributed and dynamic, with no trusted parties. This is the source code release version.

πŸ“– Read

via "Packet Storm Security".
❌ US Media, Retailers Targeted by New SparklingGoblin APT ❌

The new APT uses an undocumented backdoor to infiltrate the education, retail and government sectors.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2018-10790 β€Ό

The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to a memory allocation failure, as demonstrated by mp2aac.

πŸ“– Read

via "National Vulnerability Database".
❌ Win10 Admin Rights Tossed Off by Yet Another Plug-In ❌

Then again, you don’t even need the actual device – in this case, a SteelSeries peripheral – since emulation works just fine to launch with full SYSTEM rights.

πŸ“– Read

via "Threat Post".
πŸ” OnePercent Ransomware Group Has Hit US Companies Since November πŸ”

The group, like other malicious campaigns of late, has been using Cobalt Strike to carry out ransomware attacks against companies.

πŸ“– Read

via "".
🦿 Kanye's upcoming album is a scam magnet, Kaspersky finds 🦿

"Donda" will be out Aug. 26, and scammers are taking advantage of fan anticipation by seeding the internet with malicious fake downloads.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-21869 β€Ό

An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22244 β€Ό

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22256 β€Ό

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33015 β€Ό

Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write via an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22245 β€Ό

Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22237 β€Ό

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

πŸ“– Read

via "National Vulnerability Database".