πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41011 β€Ό

LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40875 β€Ό

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37927 β€Ό

Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37925 β€Ό

Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31836 β€Ό

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31847 β€Ό

Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code as the system user, through not correctly protecting a temporary directory used in the repair process and not checking the DLL signature.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31841 β€Ό

A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the ability to execute arbitrary code as the system user, through not checking the DLL signature.

πŸ“– Read

via "National Vulnerability Database".
❌ VMware Warns of Ransomware-Friendly Bug in vCenter Server ❌

VMware urged immediate patching of the max-severity, arbitrary file upload flaw in Analytics service, which affects all appliances running default 6.5, 6.7 and 7.0 installs.

πŸ“– Read

via "Threat Post".
❌ How REvil May Have Ripped Off Its Own Affiliates ❌

A newly discovered backdoor and double chats could have enabled REvil ransomware-as-a-service operators to hijack victim cases and snatch affiliates’ cuts of ransom payments.

πŸ“– Read

via "Threat Post".
❌ Unpatched Apple Zero-Day in macOS Finder Allows Code Execution ❌

All a user needs to do is click on an email attachment, and boom -- the code is silently executed without the victim knowing. It affects Big Sur and prior versions of macOS.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-40684 β€Ό

Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37860 β€Ό

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-6288 β€Ό

Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI.

πŸ“– Read

via "National Vulnerability Database".
🦿 Your IoT devices may be vulnerable to malware 🦿

NordPass: Only 33% of users surveyed had changed the default passwords on their IoT devices, leaving the rest vulnerable to attack.

πŸ“– Read

via "Tech Republic".
❌ Netgear SOHO Security Bug Allows RCE, Corporate Attacks ❌

The issue lies in a parental-control function that's always enabled by default, even if users don't configure for child security.

πŸ“– Read

via "Threat Post".
πŸ•΄ UK MoD Data Breach Shows Cybersecurity Must Protect Both People and Data πŸ•΄

The UK MoD has failed to protect personally identifiable information (PII) for Afghan interpreters; the incident highlights how avoidable cybersecurity mistakes can have devastating consequences.

πŸ“– Read

via "Dark Reading".
🦿 Ransomware now accounts for 69% of all attacks that use malware 🦿

The most common targets of ransomware in the second quarter of 2021 were governmental, medical and industrial companies along with scientific and educational institutions, says Positive Technologies.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-21992 β€Ό

The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit this issue to create a denial-of-service condition on the vCenter Server host.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21991 β€Ό

The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrator on the vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34647 β€Ό

The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34648 β€Ό

The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.

πŸ“– Read

via "National Vulnerability Database".