πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-42086 β€Ό

An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42094 β€Ό

An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42085 β€Ό

An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsec.ai Launches Solution to Deliver Agentless Runtime Protection for Multi-cloud Infrastructure as a Service πŸ•΄

Continuous monitoring of network traffic, data loss prevention, and responsive self-healing protection from threats to cloud-native applications.

πŸ“– Read

via "Dark Reading".
πŸ•΄ HP Extends Security Features to Work-from-Home Devices πŸ•΄

HP aims to let admins secure work-from-home endpoints by extending cloud security management that can remotely track, detect and self-heal remote company devices -- including printers.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-25271 β€Ό

A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25270 β€Ό

A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33603 β€Ό

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40832 β€Ό

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Apache HTTP Server update fails to squash path traversal, RCE bugs πŸ—“οΈ

Web admins told to upgrade (once again) to latest version

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Hardware Bolsters Medical Device Security πŸ•΄

New microprocessor technologies like secure enclaves and cryptography acceleration enable hardware to better safeguard medical devices.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-41947 β€Ό

A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Patch 'Immediately': Apache Issues Software Fix as Zero-Day Attacks Pick Up πŸ•΄

CISA reports it's seeing ongoing scanning for the flaws and expects this to accelerate.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Hong Kong’s anti-doxxing law comes into force despite human rights criticism πŸ—“οΈ

Violations could attract hefty fines and up to five years in prison

πŸ“– Read

via "The Daily Swig".
🦿 Install SELinux on Ubuntu Server 20.04: Here's how 🦿

If you've already learned SELinux, but have to deploy Ubuntu as a server operating system, you can install SELinux and be on familiar ground.

πŸ“– Read

via "Tech Republic".
⚠ Apache patch proves patchy – now you need to patch the patch ⚠

Once more unto the breach, dear friends, once more, and close up the hole of encoding dread.

πŸ“– Read

via "Naked Security".
⚠ S3 Ep53: Apple Pay, giftcards, cybermonth, and ransomware busts [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ›  nfstream 6.3.5 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Zed Attack Proxy 2.11.0 Cross Platform Package πŸ› 

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. This is the cross platform package.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2021-3312 β€Ό

An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35979 β€Ό

An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.

πŸ“– Read

via "National Vulnerability Database".