πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-24579 β€Ό

The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other installed plugins on the blog could allow such issue to be exploited and lead to RCE in some cases.

πŸ“– Read

via "National Vulnerability Database".
🦿 Paying ransom should be your last resort, cybersecurity expert says 🦿

Some organizations can get by without paying in a ransomware attack, but others really have no choice, he says.

πŸ“– Read

via "Tech Republic".
🦿 Expert: Governments and businesses must come together to combat ransomware threat 🦿

Nations have to stop sheltering bad actors in order to stop them, expert says.

πŸ“– Read

via "Tech Republic".
❌ Microsoft Exchange β€˜ProxyToken’ Bug Allows Email Snooping ❌

The bug (CVE-2021-33766) is an information-disclosure issue that could reveal victims' personal information, sensitive company data and more.

πŸ“– Read

via "Threat Post".
❌ The Underground Economy: Recon, Weaponization & Delivery for Account Takeovers ❌

In part one of a two-part series, Akamai's director of security technology and strategy, Tony Lauro, lays out what orgs need to know to defend against account takeover attacks.

πŸ“– Read

via "Threat Post".
πŸ” New DOJ Fellowship Program to Bridge Gap in Cyber Law Knowledge πŸ”

The Justice Department announced a new Cyber Fellowship program for attorneys to develop skills to handle emerging national security threats like ransomware.

πŸ“– Read

via "".
β€Ό CVE-2021-29631 β€Ό

In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O descriptors. A malicious guest may cause the device model to operate on uninitialized I/O vectors leading to memory corruption, crashing of the bhyve process, and possibly arbitrary code execution in the bhyve process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18125 β€Ό

A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22024 β€Ό

The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21774 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-21773. Reason: This candidate is a reservation duplicate of CVE-2021-21773. Notes: All CVE users should reference CVE-2021-21773 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38393 β€Ό

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37416 β€Ό

Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32991 β€Ό

Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34066 β€Ό

An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to execute system command through uploading the malicious constructed YAML file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34646 β€Ό

Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file. This allows attackers to impersonate users and trigger an email address verification for arbitrary accounts, including administrative accounts, and automatically be logged in as that user, including any site administrators. This requires the Email Verification module to be active in the plugin and the Login User After Successful Verification setting to be enabled, which it is by default.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33055 β€Ό

Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35634 β€Ό

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() sfh->boundary_entry_objects Sloop_of. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36370 β€Ό

An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3628 β€Ό

OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27020 β€Ό

Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18126 β€Ό

Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.

πŸ“– Read

via "National Vulnerability Database".