πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-34789 β€Ό

A vulnerability in the web-based management interface of Cisco Tetration could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack on an affected system. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need valid administrative credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39127 β€Ό

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40122 β€Ό

A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An attacker could exploit this vulnerability by sending a series of messages to the vulnerable API. A successful exploit could allow the attacker to cause the affected device to reload, dropping all ongoing calls and resulting in a DoS condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34743 β€Ό

A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to improper validation of cross-site request forgery (CSRF) tokens. An attacker could exploit this vulnerability by convincing a targeted user who is currently authenticated to Cisco Webex Software to follow a link designed to pass malicious input to the Cisco Webex Software application authorization interface. A successful exploit could allow the attacker to cause Cisco Webex Software to authorize an application on the user's behalf without the express consent of the user, possibly allowing external applications to read data from that user's profile.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-1529 β€Ό

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An attacker could exploit this vulnerability by authenticating to an affected device and submitting crafted input to the system CLI. A successful exploit could allow the attacker to execute commands on the underlying operating system with root privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34738 β€Ό

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42097 β€Ό

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40123 β€Ό

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative read-only privileges to download files that should be restricted. This vulnerability is due to incorrect permissions settings on an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the device. A successful exploit could allow the attacker to download files that should be restricted.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Security pre-advisories: A simple way to improve the patch management process πŸ—“οΈ

Improving enterprise security, one patch at a time

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Proposed HTTPA Protocol Uses TEEs to Secure the Web πŸ•΄

Intel researchers describe how Trusted Execution Environments can enhance HTTPS and boost web security.

πŸ“– Read

via "Dark Reading".
❌ Why is Cybersecurity Failing Against Ransomware? ❌

Hardly a week goes by without another major company falling victim to a ransomware attack. Nate Warfield, CTO at Prevailion, discusses the immense challenges in changing that status quo.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Bulletproof hosting duo jailed over support of cyber-attacks against US targets πŸ—“οΈ

Attacks leveraging defendants’ infrastructure inflicted heavy financial losses on victims

πŸ“– Read

via "The Daily Swig".
🦿 Microsoft bought CloudKnox because hybrid multicloud identity is complicated 🦿

Managing passwords and privileged access is bad enough for peopleβ€”but that's going to be dwarfed by the problem of dealing with non-human identities.

πŸ“– Read

via "Tech Republic".
πŸ•΄ How Psychology Can Save Your Cybersecurity Awareness Training Program πŸ•΄

Understanding human psychology, how it works, and how to introduce its concepts into cybersecurity awareness training can make a huge difference to your organization.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-35512 β€Ό

An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ New bug bounty platform launches for Indian ethical hackers πŸ—“οΈ

Security researchers can sign up now

πŸ“– Read

via "The Daily Swig".
🦿 How to digitally sign email in Apple Mail 🦿

Adding a digital signature to your email is just one simple step you can take in your journey for more secure communications. Jack Wallen shows you how this is done in the latest version of Apple Mail.

πŸ“– Read

via "Tech Republic".
πŸ›  AntiRansom 5 πŸ› 

AntiRansom is a tool capable of detecting and mitigating attacks of Ransomware using honeypots.

πŸ“– Read

via "Packet Storm Security".
⚠ S3 Ep55: Live malware, global encryption, dating scams, and secret emanations [Podcasts] ⚠

Latest episode - listen now! (And sign up for our forthcoming Live Malware Demo at the same time.)

πŸ“– Read

via "Naked Security".
πŸ•΄ Macs Still Targeted Mostly With Adware, Less With Malware πŸ•΄

The top 10 categories of digital threats on macOS are all adware programs, with only a sliver of the share of victims affected by actual malware, according to an IT management firm.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42740 β€Ό

The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with exec(), an attacker can inject arbitrary commands. This is because the Windows drive letter regex character class is {A-z] instead of the correct {A-Za-z]. Several shell metacharacters exist in the space between capital letter Z and lower case letter a, such as the backtick character.

πŸ“– Read

via "National Vulnerability Database".