๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.9K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โŒ How to Prevent Account Takeovers in 2021 โŒ

Dave Stewart, Approov CEO, lays out six best practices for orgs to avoid costly account takeovers.

๐Ÿ“– Read

via "Threat Post".
โ€ผ CVE-2021-36283 โ€ผ

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-21569 โ€ผ

Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-36285 โ€ผ

Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to carry out a brute force attack.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-36286 โ€ผ

Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any(non-privileged) user under some object directories, but by themselves are not sufficient to successfully escalate privileges. However, combining them with a different object, such as the NTFS junction point allows for the exploitation. Support assist clean files functionality do not distinguish junction points from the physical folder and proceeds to clean the target of the junction that allows nonprivileged users to create junction points and delete arbitrary files on the system which can be accessed only by the admin.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-36297 โ€ผ

SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-41106 โ€ผ

JWT is a library to work with JSON Web Token and JSON Web Signature. Prior to versions 3.4.6, 4.0.4, and 4.1.5, users of HMAC-based algorithms (HS256, HS384, and HS512) combined with `Lcobucci\JWT\Signer\Key\LocalFileReference` as key are having their tokens issued/validated using the file path as hashing key - instead of the contents. The HMAC hashing functions take any string as input and, since users can issue and validate tokens, users are lead to believe that everything works properly. Versions 3.4.6, 4.0.4, and 4.1.5 have been patched to always load the file contents, deprecated the `Lcobucci\JWT\Signer\Key\LocalFileReference`, and suggest `Lcobucci\JWT\Signer\Key\InMemory` as the alternative. As a workaround, use `Lcobucci\JWT\Signer\Key\InMemory` instead of `Lcobucci\JWT\Signer\Key\LocalFileReference` to create the instances of one's keys.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-21522 โ€ผ

Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-21570 โ€ผ

Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-36284 โ€ผ

Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive admin password attempt mitigations in order to carry out a brute force attack.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Outsourced Software Pose Greater Risks to Enterprise Application Security ๐Ÿ•ด

In the wake of SolarWinds and other third-party attacks, security teams worry that outsourced applications pose risks to the organization's application security, according to Dark Reading's recent "How Enterprises Are Developing Secure Applications" report.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด 75K Email Inboxes Hit in New Credential Phishing Campaign ๐Ÿ•ด

Attacker used a legitimate โ€” but likely deprecated โ€” domain to sneak malicious emails past security filters, vendor says.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2020-20122 โ€ผ

Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-20124 โ€ผ

Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-20120 โ€ผ

ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-20125 โ€ผ

EARCLINK ESPCMS-P8 contains a cross-site scripting (XSS) vulnerability in espcms_web\espcms_load.php.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ“ข What makes a password secure? ๐Ÿ“ข

IT security is constantly evolving to counter threats, but the password remains a key part of our security arsenal

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Amazon to offer cyber insurance to UK SMBs ๐Ÿ“ข

The insurance will cover risks such as accidental privacy breaches, extortion and ransomware

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Women and BAME individuals are hardest hit by cyber crime ๐Ÿ“ข

Malwarebytes calls on the technology industry to do more to provide secure internet access to everyone

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข UKโ€™s next National Cyber Strategy to reflect need for security industrial base ๐Ÿ“ข

The countryโ€™s upcoming National Cyber Security Strategy will 'hopefully' be released later this year

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Hackers spoof Zix in credential phishing attack ๐Ÿ“ข

The attack has impacted around 75,000 Office 365, Google Workspace and Exchange users

๐Ÿ“– Read

via "ITPro".