πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-40854 β€Ό

AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42342 β€Ό

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep54: Another 0-day, double Apache patch, and Fight The Phish [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
⚠ Romance scams with a cryptocurrency twist – new research from SophosLabs ⚠

Romance scams and dating site treachery with a new twist - "there's an app for that!"

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Git providers revoke weak keys generated in vulnerable GitKraken crypto library πŸ—“οΈ

Weak SSH keys have been revoked by vendors to protect their users

πŸ“– Read

via "The Daily Swig".
πŸ•΄ 6 Lessons From the Expiration of the Let's Encrypt Root Certificate πŸ•΄

Fallout from the transition highlights the need for organizations to monitor and have processes for updating CA roots, experts say.

πŸ“– Read

via "Dark Reading".
❌ Podcast: 67% of Orgs Have Been Hit by Ransomware at Least Once ❌

Fortinet’s Derek Manky discusses a recent global survey showing that two-thirds of organizations suffered at least one ransomware attack, while half were hit multiple times.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Israeli hospital cancels non-urgent procedures following ransomware attack πŸ—“οΈ

National cybersecurity agency braced for further serious network intrusions

πŸ“– Read

via "The Daily Swig".
πŸ•΄ How Security Teams Can Reinforce End-User Awareness πŸ•΄

Training programs provide the information, but security teams can reinforce these for better end-user education.

πŸ“– Read

via "Dark Reading".
❌ CryptoRom Scam Rakes in $1.4M by Exploiting Apple Enterprise Features ❌

The campaign, which uses the Apple Developer Program and Enterprise Signatures to get past Apple's app review process, remains active.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Dutch police warn DDoS-for-hire customers to desist or face prosecution πŸ—“οΈ

We know what you DDoSed last summer

πŸ“– Read

via "The Daily Swig".
🦿 How to configure SSH to use a non-standard port with SELinux set to enforcing 🦿

Switching the SSH listening port is an easy way to help secure remote login on your Linux servers. But when SELinux is involved, you have to take a few extra steps. Jack Wallen shows you how.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-19961 β€Ό

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33177 β€Ό

The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19964 β€Ό

A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20599 β€Ό

Authorization bypass through user-controlled key vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU all versions and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU all versions allows an remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19960 β€Ό

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19962 β€Ό

A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22963 β€Ό

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19957 β€Ό

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19954 β€Ό

An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".