๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.9K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โŒ Google Crushes YouTube Cookie-Stealing Channel Hijackers โŒ

Google has caught and brushed off a bunch of cookie-stealing YouTube channel hijackers who were running cryptocurrency scams on, or auctioning off, ripped-off channels. 

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด Removing Friction for the Enterprise With Trusted Access ๐Ÿ•ด

Our work lives are supposed to be simpler and easier because of technology. At least thatโ€™s the promise.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2021-42762 โ€ผ

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-41167 โ€ผ

modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should limit the concurrency of some actions but, in practice, they don't. Any code calling these functions will be written thinking they would limit the concurrency but they won't. This could lead to potential security issues in other projects. The problem has been patched in 1.0.4. There is no workaround.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38896 โ€ผ

IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209566.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-41135 โ€ผ

The Cosmos-SDK is a framework for building blockchain applications in Golang. Affected versions of the SDK were vulnerable to a consensus halt due to non-deterministic behaviour in a ValidateBasic method in the x/authz module. The MsgGrant of the x/authz module contains a Grant field which includes a user-defined expiration time for when the authorization grant expires. In Grant.ValidateBasic(), that time is compared to the nodeรƒยขรขโ€šยฌรขโ€žยขs local clock time. Any chain running an affected version of the SDK with the authz module enabled could be halted by anyone with the ability to send transactions on that chain. Recovery would require applying the patch and rolling back the latest block. Users are advised to update to version 0.44.2.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Execs From Now-Defunct GigaTrust Arrested in $50M Fraud Scheme ๐Ÿ•ด

Email endpoint security-as-a-service company founder and two others indicted in an elaborate financial fraud scheme.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด MITRE Engenuity Announces ATT&CKยฎ Evaluations Call for Participation for Managed Services ๐Ÿ•ด

Offering to provide transparency into the capabilities of managed security service providers and and managed detection and response competencies.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Google: Phishing Campaign Targets YouTube Creators ๐Ÿ•ด

The attackers behind the campaign, which distributes cookie theft malware, are attributed to actors recruited in a Russian-speaking forum.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด CISA Awards $2 Million to Bring Cybersecurity Training to Rural Communities and Diverse Populations ๐Ÿ•ด

Award recipients NPower and CyberWarrior recognized for development of cyber workforce training programs.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Microsoft, Intel, and Goldman Sachs to Lead New TCG Work Group to Tackle Supply Chain Security Challenges ๐Ÿ•ด

Led by representatives from the three companies, the work group will create guidance that defines, implements, and upholds security standards for the entire supply chain.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Optiv Announces Second Annual $40,000 Scholarship for Black, African American Identifying STEM Students ๐Ÿ•ด

$10,000 to be awarded annually for four years each by Optivโ€™s Black Employee Network.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Microsoft-Signed Rootkit Targets Gaming Environments in China ๐Ÿ•ด

FiveSys is the second publicly known rootkit since June that attackers have managed to sneak past Microsoft's driver certification process.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2021-42771 โ€ผ

Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42765 โ€ผ

The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to leverage network delay to cause a denial of service (indefinite stalling of consensus decisions).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42766 โ€ผ

The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service (long-range consensus chain reorganizations), even when this adversary has little stake and cannot influence network message propagation. This can cause a protocol stall, or an increase in the profits of individual validators.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42764 โ€ผ

The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service (delayed consensus decisions), and also increase the profits of individual validators, via short-range reorganizations of the underlying consensus chain.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-40121 โ€ผ

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-34736 โ€ผ

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-39126 โ€ผ

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in the referrer headers which discloses a user's CSRF token. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42096 โ€ผ

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.

๐Ÿ“– Read

via "National Vulnerability Database".