🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2021-42093

An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.

📖 Read

via "National Vulnerability Database".
CVE-2021-42087

An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.

📖 Read

via "National Vulnerability Database".
CVE-2021-42092

An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.

📖 Read

via "National Vulnerability Database".
CVE-2021-42090

An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.

📖 Read

via "National Vulnerability Database".
CVE-2021-42084

An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.

📖 Read

via "National Vulnerability Database".
CVE-2021-42091

An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.

📖 Read

via "National Vulnerability Database".
CVE-2021-42088

An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.

📖 Read

via "National Vulnerability Database".
CVE-2021-42095

Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.

📖 Read

via "National Vulnerability Database".
CVE-2020-21865

ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.

📖 Read

via "National Vulnerability Database".
CVE-2021-42086

An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.

📖 Read

via "National Vulnerability Database".
CVE-2021-42094

An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.

📖 Read

via "National Vulnerability Database".
CVE-2021-42085

An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.

📖 Read

via "National Vulnerability Database".
🕴 Microsec.ai Launches Solution to Deliver Agentless Runtime Protection for Multi-cloud Infrastructure as a Service 🕴

Continuous monitoring of network traffic, data loss prevention, and responsive self-healing protection from threats to cloud-native applications.

📖 Read

via "Dark Reading".
🕴 HP Extends Security Features to Work-from-Home Devices 🕴

HP aims to let admins secure work-from-home endpoints by extending cloud security management that can remotely track, detect and self-heal remote company devices -- including printers.

📖 Read

via "Dark Reading".
CVE-2021-25271

A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.

📖 Read

via "National Vulnerability Database".
CVE-2021-25270

A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.

📖 Read

via "National Vulnerability Database".
CVE-2021-33603

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

📖 Read

via "National Vulnerability Database".
CVE-2021-40832

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

📖 Read

via "National Vulnerability Database".
🗓️ Apache HTTP Server update fails to squash path traversal, RCE bugs 🗓️

Web admins told to upgrade (once again) to latest version

📖 Read

via "The Daily Swig".
🕴 Hardware Bolsters Medical Device Security 🕴

New microprocessor technologies like secure enclaves and cryptography acceleration enable hardware to better safeguard medical devices.

📖 Read

via "Dark Reading".
CVE-2021-41947

A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.

📖 Read

via "National Vulnerability Database".