πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ The Ransomware Payment Dilemma: Should Victims Pay or Not? πŸ•΄

It's time to steer the conversation away from whether payment bans should be implemented to how and when they should take effect.

πŸ“– Read

via "Dark Reading".
πŸ•΄ JavaScript Packing Found In More Than 25% of Malicious Sites πŸ•΄

Obfuscation techniques are extremely prevalent, data shows, but they can't be used as a single indicator of compromise because legitimate websites use them.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-25969 β€Ό

In Ò€œCamaleon CMSҀ� application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows unprivileged application users to store malicious scripts in the comments section of the post. These scripts are executed in a victimÒ€ℒs browser when they open the page containing the malicious comment.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23452 β€Ό

This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25972 β€Ό

In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25970 β€Ό

Camaleon CMS 0.1.7 to 2.6.0 doesnÒ€ℒt terminate the active session of the users, even after the admin changes the userÒ€ℒs password. A user that was already logged in, will still have access to the application even after the password was changed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25971 β€Ό

In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Historic scientific notation bug foils WAF defenses πŸ—“οΈ

AWS WAF and ModSecurity get β€˜blinded by science’

πŸ“– Read

via "The Daily Swig".
⚠ β€œTo the moon!” Cryptocurrency hamster Mr Goxx trades online 24/7 ⚠

Here's a happy cryptocurrency story for once, with not a cybercrook in sight.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-21747 β€Ό

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3542 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42739. Reason: This candidate is a reservation duplicate of CVE-2021-42739. Notes: All CVE users should reference CVE-2021-42739 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21746 β€Ό

ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Passwordless Is the Future … but What About the Present? πŸ•΄

Password managers, single sign-on, and multifactor authentication each offers its own methodology and unique set of benefits β€” and drawbacks β€” to users.

πŸ“– Read

via "Dark Reading".
❌ VPN Exposes Data for 1M Users, Leading to Researcher Questioning ❌

Experts warn that virtual private networks are increasingly vulnerable to leaks and attack.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-21749 β€Ό

ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21743 β€Ό

ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21744 β€Ό

ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of the device, causing some security functions of the device to be disabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21745 β€Ό

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21748 β€Ό

ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Government Agencies Warn Against BlackMatter Ransomware πŸ”

CISA, the FBI, and NSA provided defenders with tips to protect networks and mitigations to prevent the spread of the ransomware.

πŸ“– Read

via "".
❌ Google Crushes YouTube Cookie-Stealing Channel Hijackers ❌

Google has caught and brushed off a bunch of cookie-stealing YouTube channel hijackers who were running cryptocurrency scams on, or auctioning off, ripped-off channels. 

πŸ“– Read

via "Threat Post".