‼ CVE-2021-25475 ‼
📖 Read
via "National Vulnerability Database".
A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25477 ‼
📖 Read
via "National Vulnerability Database".
An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25467 ‼
📖 Read
via "National Vulnerability Database".
Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows privilege escalation to Root by hijacking loaded library.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25474 ‼
📖 Read
via "National Vulnerability Database".
Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25471 ‼
📖 Read
via "National Vulnerability Database".
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25483 ‼
📖 Read
via "National Vulnerability Database".
Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25472 ‼
📖 Read
via "National Vulnerability Database".
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-41126 ‼
📖 Read
via "National Vulnerability Database".
October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts which had previously been deleted may still be able to sign in to the backend using October CMS v2.0. The issue has been patched in v2.1.12 of the october/october package. There are no workarounds for this issue and all users should update.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-29908 ‼
📖 Read
via "National Vulnerability Database".
The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authentication. IBM X-Force ID: 207747.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25478 ‼
📖 Read
via "National Vulnerability Database".
A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25481 ‼
📖 Read
via "National Vulnerability Database".
An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP Memory.📖 Read
via "National Vulnerability Database".
❌ VMware ESXi Servers Encrypted by Lightning-Fast Python Script ❌
📖 Read
via "Threat Post".
The little snippet of Python code strikes fast and nasty, taking less than three hours to complete a ransomware attack from initial breach to encryption.📖 Read
via "Threat Post".
Threat Post
VMware ESXi Servers Encrypted by Lightning-Fast Python Script
It's a little snippet of Python code – 6KB – that strikes fast and nasty, taking less than three hours to complete from initial breach to encryption.
🕴 Aerospace, Telecommunications Companies Victims of Stealthy Iranian Cyber-Espionage Campaign 🕴
📖 Read
via "Dark Reading".
Since at least 2018, "MalKamak" group has targeted firms in the Middle East, Russia, and other areas to steal sensitive data, security vendor says.📖 Read
via "Dark Reading".
Dark Reading
Aerospace, Telecommunications Companies Victims of Stealthy Iranian Cyber-Espionage Campaign
Since at least 2018, "MalKamak" group has targeted firms in the Middle East, Russia, and other areas to steal sensitive data, security vendor says.
🕴 MacOS Security: What Security Teams Should Know 🕴
📖 Read
via "Dark Reading".
As more macOS patches emerge and cybercriminals and nation-states take aim at the platform, experts discuss how macOS security has evolved and how businesses can protect employees.📖 Read
via "Dark Reading".
Dark Reading
MacOS Security: What Security Teams Should Know
As more macOS patches emerge and cybercriminals and nation-states take aim at the platform, experts discuss how macOS security has evolved and how businesses can protect employees.
❌ Canopy Parental Control App Wide Open to Unpatched XSS Bugs ❌
📖 Read
via "Threat Post".
The possible cyberattacks include disabling monitoring, location-tracking of children and malicious redirects of parent-console users.📖 Read
via "Threat Post".
Threat Post
Canopy Parental Control App Wide Open to Unpatched XSS Bugs
The possible cyberattacks include disabling monitoring, location-tracking of children and malicious redirects of parent-console users.
🕴 Space ISAC and NY Metro InfraGard Members Alliance Announce Collaboration to Advance the Mission of Cybersecurity in Space 🕴
📖 Read
via "Dark Reading".
The collaboration is designed to promote broad-based participation by members of both organizations through enhanced educational initiatives, user-and operator-training, and intelligence-sharing activities in the space domain.📖 Read
via "Dark Reading".
Dark Reading
Space ISAC and NY Metro InfraGard Members Alliance Announce Collaboration to Advance the Mission of Cybersecurity in Space
The collaboration is designed to promote broad-based participation by members of both organizations through enhanced educational initiatives, user-and operator-training, and intelligence-sharing activities in the space domain.
🕴 5-Year Breach May Have Exposed Billions of Text Messages 🕴
📖 Read
via "Dark Reading".
The attack affected Syniverse, a major telecom company that annually routes billions of text messages for hundreds of mobile carriers.📖 Read
via "Dark Reading".
Dark Reading
5-Year Breach May Have Exposed Billions of Text Messages
The attack affected Syniverse, a major telecom company that annually routes billions of text messages for hundreds of mobile carriers.
‼ CVE-2021-34735 ‼
📖 Read
via "National Vulnerability Database".
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-34710 ‼
📖 Read
via "National Vulnerability Database".
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-34742 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-34775 ‼
📖 Read
via "National Vulnerability Database".
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches. An unauthenticated, adjacent attacker could perform the following: Execute code on the affected device or cause it to reload unexpectedly Cause LLDP database corruption on the affected device For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). Cisco has released firmware updates that address these vulnerabilities.📖 Read
via "National Vulnerability Database".