πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Firefox 93 lands with HTTP download blocking, new user privacy features πŸ—“οΈ

Roadblocks erected against untrusted content and unwanted ads

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Multiple XSS vulnerabilities in child monitoring app Canopy β€˜could risk location leak’ πŸ—“οΈ

Pair of unpatched security bugs are β€˜just the tip of the iceberg’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ A Culture of Unity Is Key to Solving the Cyber Challenge πŸ•΄

Lack of unity in vendor solutions and in security teams' culture are detrimental to a successful and productive security strategy.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-19003 β€Ό

An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.

πŸ“– Read

via "National Vulnerability Database".
🦿 How a phishing attack thwarted MFA to steal money from Coinbase customers 🦿

A flaw in Coinbase's setup of SMS-based MFA allowed attackers to compromise a large number of accounts.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Optiv Rebrands as Cyber Advisory & Solutions Leader πŸ•΄

Optiv announced it will create a new market category to protect business value and accelerate performance.

πŸ“– Read

via "Dark Reading".
❌ Twitch Gets Gutted: All Source Code Leaked ❌

An anonymous user posted a link to a 125GB torrent to 4chan yesterday, containing all of Twitch's source code, comments going back to its inception and more.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ OPPA: Ohio could become the third US state to enact a new consumer privacy law in 2021 πŸ—“οΈ

Ohio Personal Privacy Act will grant Ohioans an expansive set of new rights, writes US attorney David Oberly

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-0635 β€Ό

When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss of user rights.Product: Androidversion:Android-10Android ID: A-189402477

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0693 β€Ό

In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-184046948

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28702 β€Ό

PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform tasks such as legacy USB emulation. If such a device is passed through to a guest, then on guest shutdown the device is not properly deassigned. The IOMMU configuration for these devices which are not properly deassigned ends up pointing to a freed data structure, including the IO Pagetables. Subsequent DMA or interrupts from the device will have unpredictable behaviour, ranging from IOMMU faults to memory corruption.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0682 β€Ό

In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-159624555

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0695 β€Ό

In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-184018316References: Upstream kernel

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0644 β€Ό

In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-181053462

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0598 β€Ό

In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-180422108

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0683 β€Ό

In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-185398942

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0636 β€Ό

When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss of user rights.Product: Androidversion: Android-10Android ID: A-189392423

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0681 β€Ό

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-192535337

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0684 β€Ό

In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-179839665

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0688 β€Ό

In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-161149543

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0691 β€Ό

In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-188554048

πŸ“– Read

via "National Vulnerability Database".