πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41457 β€Ό

There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a denial of service vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41110 β€Ό

cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no available workarounds aside from installing the patch. The SnakeYaml constructor, by default, allows any data to be parsed. To fix the issue the object needs to be created with a `SafeConstructor` object, as seen in the patch.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41459 β€Ό

There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter which leads to a denial of service vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41456 β€Ό

There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter which leads to a denial of service vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35297 β€Ό

Scalabium dBase Viewer version 2.6 (Build 5.751) is vulnerable to remote code execution via a crafted DBF file that triggers a buffer overflow. An attacker can use the Structured Exception Handler (SEH) records and redirect execution to attacker-controlled code.

πŸ“– Read

via "National Vulnerability Database".
🦿 Google stakes new Secure Open Source rewards program for developers with $1M seed money 🦿

The SOS program, run by the Linux Foundation, will reward developers with potentially more than $10,000 for enhancing the security of critical open source software.

πŸ“– Read

via "Tech Republic".
β™ŸοΈ FCC Proposal Targets SIM Swapping, Port-Out Fraud β™ŸοΈ

The U.S. Federal Communications Commission (FCC) is asking for feedback on new proposed rules to crack down on SIM swapping and number port-out fraud, increasingly prevalent scams in which identity thieves hijack a target's mobile phone number and use that to wrest control over the victim's online identity.

πŸ“– Read

via "Krebs on Security".
πŸ—“οΈ Prototype pollution vulnerabilities rife among high-traffic websites, study finds πŸ—“οΈ

Technique is exploitable at scale because it’s so overlooked, speculate researchers

πŸ“– Read

via "The Daily Swig".
πŸ•΄ CISA and Girls Who Code Partner to Create Career Pathways for Young Women πŸ•΄

Through this partnership, CISA and Girls Who Code will establish collaborative opportunities to provide awareness, training, and pathways into cybersecurity careers for girls, women, and those who identify as nonbinary.

πŸ“– Read

via "Dark Reading".
❌ Flubot Malware Targets Androids With Fake Security Updates ❌

The banking trojan keeps switching up its lies, trying to fool Android users into clicking on a fake Flubot-deleting app or supposedly uploaded photos of recipients.

πŸ“– Read

via "Threat Post".
⚠ Gift card fraud – four suspects hit with money laundering charges ⚠

Gift card fraud may sound like small beer against ransomware - but it's personal, it hurts, and it's still a multi-million dollar problem.

πŸ“– Read

via "Naked Security".
⚠ How to steal money via Apple Pay using the β€œExpress Transit” feature ⚠

Could a rogue vendor with a dodgy payment terminal rip you off via Apple Pay? Maybe. Here's what to do about it.

πŸ“– Read

via "Naked Security".
⚠ S3 Ep52: Let’s Encrypt, Outlook leak, and VMware exploit [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ›  Falco 0.30.0 πŸ› 

Sysdig Falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Read

via "Packet Storm Security".
πŸ›  SQLMAP - Automatic SQL Injection Tool 1.5.10 πŸ› 

sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2021-29108 β€Ό

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker to impersonate another account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29110 β€Ό

Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40960 β€Ό

Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41647 β€Ό

An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41649 β€Ό

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41648 β€Ό

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.

πŸ“– Read

via "National Vulnerability Database".