πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-40887 β€Ό

Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Oregon Eye Specialists discloses data breach following employee email compromise πŸ—“οΈ

Attackers had access to mailboxes over a two-month period

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Continuous Authentication Tech Looms Large in Deployment Plans πŸ•΄

Data from the Dark Reading and Omdia Enterprise Security in a Post Pandemic World report shows security leaders are interested in continuous authentication technologies, especially behavioral-based capabilities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Applying Behavioral Psychology to Strengthen Your Incident Response Team πŸ•΄

A deep-dive study on the inner workings of incident response teams leads to a framework to apply behavioral psychology principles to CSIRTs.

πŸ“– Read

via "Dark Reading".
⚠ Apache patch proves patchy – now you need to patch the patch ⚠

Once more unto the breach, dear friends, once more, and close up the hole of encoding dread.

πŸ“– Read

via "Naked Security".
πŸ•΄ The 5 Phases of Zero Trust Adoption πŸ•΄

Zero trust aims to replace implicit trust with explicit, continuously adaptive trust across users, devices, networks, applications, and data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-40543 β€Ό

Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40542 β€Ό

Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29006 β€Ό

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29005 β€Ό

Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29004 β€Ό

rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a webshell to the server and access it remotely.

πŸ“– Read

via "National Vulnerability Database".
🦿 How to combat the most prevalent ransomware threats 🦿

Over the second quarter of the year, 73% of ransomware detections were related to the REvil/Sodinokibi family, while Darkside attacks expanded to more industries, McAfee says.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Ransom Disclosure Act: US bill mandates organizations to report ransomware payments πŸ—“οΈ

Newly proposed law hopes to further understanding of cybercrime landscape

πŸ“– Read

via "The Daily Swig".
⚠ Cybersecurity awareness month: Fight the phish! ⚠

Phishing crooks get to try over and over again. But you only have to make one mistake...

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Ransomware forensics research reveals cybercrime tradecraft secrets πŸ—“οΈ

Resident REvil

πŸ“– Read

via "The Daily Swig".
πŸ•΄ IDrive Remote Desktop Offers Protection from RDP Cyberattacks and Vulnerabilities πŸ•΄

Remote Desktop aims to solve vulnerability issues with RDP by implementing robust access and security controls.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Forcepoint to Acquire Bitglass πŸ•΄

Deal will merge Bitglass's security service edge technology with Forcepoint’s SASE architecture.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-40541 β€Ό

PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40191 β€Ό

Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz/attach/Uploader.class.php and return a wrong response in content-type of output data in webroot/dzz/attach/controller.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0583 β€Ό

In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-182282956

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27002 β€Ό

NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy.

πŸ“– Read

via "National Vulnerability Database".