πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-25964 β€Ό

In Ò€œCalibre-webҀ� application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in Ò€œMetadataҀ�. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38822 β€Ό

A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38823 β€Ό

The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36051 β€Ό

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a specially-crafted .cpp file.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Let's Encrypt root cert update catches out many big-name tech firms πŸ—“οΈ

Back on the chain gang

πŸ“– Read

via "The Daily Swig".
πŸ›  TestSSL 3.0.6 πŸ› 

testssl.sh is a free command line tool which checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws, and much more. It is written in (pure) bash, makes only use of standard Unix utilities, openssl and last but not least bash sockets.

πŸ“– Read

via "Packet Storm Security".
πŸ›  MedSec Network Utility Tool πŸ› 

MedSec is a network utility tool developed to perform some network, security administrator, and pentesting tasks. Basic functionality includes port scans, host discovery, banner grabbing, dns checks, subdomain enumeration, and more.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Seth RDP Man-In-The-Middle Tool πŸ› 

Seth is a tool written in Python and Bash to MitM RDP connections by attempting to downgrade the connection in order to extract clear text credentials. It was developed to raise awareness and educate about the importance of properly configured RDP connections in the context of pentests, workshops or talks.

πŸ“– Read

via "Packet Storm Security".
πŸ›  PyRDP RDP Man-In-The-Middle Tool πŸ› 

PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Bing.com Hostname / IP Enumerator 1.0.5 πŸ› 

This tool enumerates hostnames from Bing.com for an IP address. Bing.com is Microsoft's search engine which has an IP: search parameter. Written in Bash for Linux. Requires wget.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Mandiant Confirms Name Change from FireEye, Inc. to Mandiant, Inc. πŸ•΄

The decision to change the corporate name and stock ticker symbol reflects the company’s strategy to focus on Mandiant’s security controls-agnostic solutions delivered through the Mandiant Advantage cloud-based platform.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA Kicks Off Cybersecurity Awareness Month πŸ•΄

CISA will dedicate October to encourage everyone to be cyber smart.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-41530 β€Ό

Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerability, if HTTP User Response has been configured.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39871 β€Ό

In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41596 β€Ό

SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39879 β€Ό

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40683 β€Ό

In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39873 β€Ό

In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35296 β€Ό

An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39899 β€Ό

In all versions of GitLab CE/EE, an attacker with physical access to a userÒ€ℒs machine may brute force the userÒ€ℒs password via the change password function. There is a rate limit in place, but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39874 β€Ό

In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

πŸ“– Read

via "National Vulnerability Database".