๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2021-32137 โ€ผ

Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-32132 โ€ผ

The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-32134 โ€ผ

The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-32135 โ€ผ

The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  Serious Security: How to make sure you donโ€™t miss bug reports! โš 

Hey, let's create a text file that lists our security contacts! We'll call it... security DOT txt.

๐Ÿ“– Read

via "Naked Security".
โš  S3 Ep49: Poison PACs, pointless alarms and phunky bugs [Podcast] โš 

Latest episode - listen now!

๐Ÿ“– Read

via "Naked Security".
๐Ÿฆฟ IoT device attacks double in the first half of 2021, and remote work may shoulder some of the blame ๐Ÿฆฟ

The smart home could be ripe for IoT device attacks as cybercriminals rake in record ransomware payments. Remote work may be responsible for the increase in attacks, Kaspersky says.

๐Ÿ“– Read

via "Tech Republic".
โŒ Honing Cybersecurity Strategy When Everyoneโ€™s a Target for Ransomware โŒ

Aamir Lakhani, researcher at FortiGuard Labs, explains why organizations must extend cyber-awareness training across the entire enterprise, from Luddites to the C-suite.

๐Ÿ“– Read

via "Threat Post".
โŒ WooCommerce Multi Currency Bug Allows Shoppers to Change eCommerce Pricing โŒ

The security vulnerability can be exploited with a malicious CSV file.

๐Ÿ“– Read

via "Threat Post".
โŒ WhatsAppโ€™s End-to-End Encryption Isnโ€™t Actually Broken โŒ

WhatsAppโ€™s moderators sent messages flagged by intended recipients. Researchers say this isn't concerning -- yet.

๐Ÿ“– Read

via "Threat Post".
๐Ÿฆฟ How to utilize openssl in Linux to check SSL certificate details ๐Ÿฆฟ

SSL certificates are an integral component in securing data and connectivity to other systems. Learn tips on how you can use the Linux openssl command to find critical certificate details.

๐Ÿ“– Read

via "Tech Republic".
โŒ REvilโ€™s Back; Coder Fat-Fingered Away Its Decryptor Key โŒ

How did Kaseya get a universal decryptor after a mind-bogglingly big ransomware attack? A REvil coder misclicked, generated & issued it, and โ€œThatโ€™s how we sh*t ourselves.โ€

๐Ÿ“– Read

via "Threat Post".
๐Ÿ” Jury Convicts Ex-Employee in Tech Trade Secret Theft Case ๐Ÿ”

The conviction came just days before National Insider Threat Awareness Month, a government campaign designed to boost awareness around insider threats and identifying risky behavior.

๐Ÿ“– Read

via "".
โ€ผ CVE-2021-24621 โ€ผ

The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capability is disallowed, which could lead to Stored Cross-Site Scripting issues

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38833 โ€ผ

SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-33546 โ€ผ

Multiple camera devices by UDP Technology, Geutebrรƒฦ’ร‚ยผck and other vendors are vulnerable to a stack-based buffer overflow condition in the name parameter, which may allow an attacker to remotely execute arbitrary code.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-33550 โ€ผ

Multiple camera devices by UDP Technology, Geutebrรƒฦ’ร‚ยผck and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24490 โ€ผ

The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the presence of a .htaccess, denying access to everything in the folder the file is uploaded to, the malicious uploaded file will only be accessible on Web Servers such as Nginx/IIS

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-33544 โ€ผ

Multiple camera devices by UDP Technology, Geutebrรƒฦ’ร‚ยผck and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24510 โ€ผ

The MF Gig Calendar WordPress plugin through 1.1 does not sanitise or escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-33551 โ€ผ

Multiple camera devices by UDP Technology, Geutebrรƒฦ’ร‚ยผck and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

๐Ÿ“– Read

via "National Vulnerability Database".