πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-37539 β€Ό

Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Telos, Splunk, stackArmor, AWS Announce FASTTR Initiative to Accelerate Compliance πŸ•΄

FASTTR initiative enhances stackArmor's ThreatAlert by building on market-leading Telos' Xacta for security compliance documentation and Splunk for security information and event management.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zero Trust Comes to Industry's Broadest Cybersecurity Platform πŸ•΄

Trend Micro Zero Trust Risk Insights continuously reveals and prioritizes risks for better decision making.

πŸ“– Read

via "Dark Reading".
πŸ•΄ BloodyStealer: Advanced New Trojan Targets Accounts of Popular Online Gaming Platforms πŸ•΄

Kaspersky researchers have discovered an advanced Trojan, dubbed BloodyStealer, sold on darknet forums and used to steal gamers’ accounts on popular gaming platforms, including Steam, Epic Games Store, and EA Origin.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cloudflare Ventures into Simplifying Email Security πŸ•΄

The company adds complex email security technologies β€” including the alphabet soup of SPF, DKIM, and DMARC β€” as part of its service.

πŸ“– Read

via "Dark Reading".
🦿 Compromising a government network is so simple, an out-of-the-box, dark web RAT can do it 🦿

Commercially-available malware, with minimal modification, is behind attacks against the Indian government, says Cisco's Talos security research group.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-24633 β€Ό

The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40709 β€Ό

Adobe Photoshop versions 21.2.11 (and earlier) and 22.5 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted SVG file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40700 β€Ό

Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24666 β€Ό

The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36877 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24659 β€Ό

The PostX ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39818 β€Ό

Adobe InCopy version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24610 β€Ό

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23445 β€Ό

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24660 β€Ό

The PostX ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24661 β€Ό

The PostX ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40712 β€Ό

Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authenticated attacker can send a malformed POST request to achieve server-side denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40702 β€Ό

Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40329 β€Ό

The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39827 β€Ό

Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary file write vulnerability in the Digital Editions installer. An authenticated attacker could leverage this vulnerability to write an arbitrary file to the system. User interaction is required before product installation to abuse this vulnerability.

πŸ“– Read

via "National Vulnerability Database".