πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-42369 β€Ό

Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36389 β€Ό

In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36387 β€Ό

In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36388 β€Ό

In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".

πŸ“– Read

via "National Vulnerability Database".
🦿 How a vishing attack spoofed Microsoft to try to gain remote access 🦿

A voice phishing campaign spotted by Armorblox tried to convince people to give the attackers access to their computer.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Deepfence Announces Open Source Availability of ThreatMapper πŸ•΄

Cloud native security observability platform seamlessly scans, maps, and ranks application vulnerabilities from development through critical production stage.

πŸ“– Read

via "Dark Reading".
❌ Rickroll Grad Prank Exposes Exterity IPTV Bug ❌

IPTV and IP video security is increasingly under scrutiny, even by high school kids.

πŸ“– Read

via "Threat Post".
πŸ•΄ Increased Security Spending to Support Distributed Workforce πŸ•΄

Security leaders are deploying or actively considering cloud security, threat intel, and XDR technologies.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Enterprise Data Storage Environments Riddled With Vulnerabilities πŸ•΄

Many organizations are not properly protecting their storage and backup systems from compromise, new study finds.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42340 β€Ό

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38295 β€Ό

In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Injection vulnerabilities in popular WordPress plugin could expose credentials, allow admin access πŸ—“οΈ

Fastest Cache is used by more than one million people

πŸ“– Read

via "The Daily Swig".
πŸ•΄ From Help Desk to Head of SOC: Building a Cybersecurity Career on Empathy and Candor πŸ•΄

Why a passion for helping people is key to delivering effective cybersecurity solutions.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-37737 β€Ό

A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39332 β€Ό

The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization found throughout the plugin which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.4.5. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42332 β€Ό

The Ò€œList ViewҀ� function of ShinHer StudyOnline System is not under authority control. After logging in with userÒ€ℒs privilege, remote attackers can access the content of other usersÒ€ℒ message boards by crafting URL parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40999 β€Ό

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38431 β€Ό

An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39335 β€Ό

The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/admin/class/class-wpgenious-job-listing-options.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.2. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39344 β€Ό

The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/class-kjm-admin-notices-admin.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39349 β€Ό

The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/wp-hal.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.1.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

πŸ“– Read

via "National Vulnerability Database".