πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-42084 β€Ό

An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42091 β€Ό

An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42088 β€Ό

An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42095 β€Ό

Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21865 β€Ό

ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42086 β€Ό

An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42094 β€Ό

An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42085 β€Ό

An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsec.ai Launches Solution to Deliver Agentless Runtime Protection for Multi-cloud Infrastructure as a Service πŸ•΄

Continuous monitoring of network traffic, data loss prevention, and responsive self-healing protection from threats to cloud-native applications.

πŸ“– Read

via "Dark Reading".
πŸ•΄ HP Extends Security Features to Work-from-Home Devices πŸ•΄

HP aims to let admins secure work-from-home endpoints by extending cloud security management that can remotely track, detect and self-heal remote company devices -- including printers.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-25271 β€Ό

A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25270 β€Ό

A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33603 β€Ό

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40832 β€Ό

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Apache HTTP Server update fails to squash path traversal, RCE bugs πŸ—“οΈ

Web admins told to upgrade (once again) to latest version

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Hardware Bolsters Medical Device Security πŸ•΄

New microprocessor technologies like secure enclaves and cryptography acceleration enable hardware to better safeguard medical devices.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-41947 β€Ό

A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Patch 'Immediately': Apache Issues Software Fix as Zero-Day Attacks Pick Up πŸ•΄

CISA reports it's seeing ongoing scanning for the flaws and expects this to accelerate.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Hong Kong’s anti-doxxing law comes into force despite human rights criticism πŸ—“οΈ

Violations could attract hefty fines and up to five years in prison

πŸ“– Read

via "The Daily Swig".
🦿 Install SELinux on Ubuntu Server 20.04: Here's how 🦿

If you've already learned SELinux, but have to deploy Ubuntu as a server operating system, you can install SELinux and be on familiar ground.

πŸ“– Read

via "Tech Republic".
⚠ Apache patch proves patchy – now you need to patch the patch ⚠

Once more unto the breach, dear friends, once more, and close up the hole of encoding dread.

πŸ“– Read

via "Naked Security".