πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Friday Five 10/22 πŸ”

A GPS software bug, helping nonprofits defend against nation state attacks, and the DOJ wants more incident reporting - catch up on the infosec news of the week with the Friday Five!

πŸ“– Read

via "".
πŸ•΄ 7 Ways to Lock Down Enterprise Printers πŸ•΄

Following the PrintNightmare case, printer security has become a hot issue for security teams. Here are seven ways to keep printers secure on enterprise networks.

πŸ“– Read

via "Dark Reading".
❌ REvil Servers Shoved Offline by Governments – But They’ll Be Back, Researchers Say ❌

A multi-country effort has given ransomware gang REvil a taste of its own medicine by pwning its backups and pushing its leak site and Tor payment site offline.

πŸ“– Read

via "Threat Post".
πŸ•΄ 'TodayZoo' Phishing Kit Cobbled Together From Other Malware πŸ•΄

Microsoft's analysis of a recent phishing attack shows how cybercriminals are mixing and matching to efficiently develop their attack frameworks.

πŸ“– Read

via "Dark Reading".
❌ FIN7 Lures Unwitting Security Pros to Carry Out Ransomware Attacks ❌

The infamous Carbanak operator is moving is looking to juice its ransomware game by recruiting IT staff to its fake Bastion Secure 'pen-testing' company.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-42840 β€Ό

SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42556 β€Ό

Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42836 β€Ό

GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41171 β€Ό

eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a brute-force protection mechanism by using many different forged PHPSESSID values in HTTP Cookie header. This issue has been addressed by implementing brute force login protection, as recommended by Owasp with Device Cookies. This mechanism will not impact users and will effectively thwart any brute-force attempts at guessing passwords. The only correct way to address this is to upgrade to version 4.1.0. Adding rate limitation upstream of the eLabFTW service is of course a valid option, with or without upgrading.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29835 β€Ό

IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204833.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ aDolus raises $2.5 million to secure critical infrastructure and grow sales and marketing team πŸ•΄

Software supply chain security experts to drive aggressive go-to-market strategy

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-36485 β€Ό

Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPEG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23060 β€Ό

Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability allows attackers to escalate local process privileges via a crafted ef2 file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28968 β€Ό

Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username input field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28957 β€Ό

Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the name, firstname, or username input fields.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36491 β€Ό

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36493 β€Ό

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36490 β€Ό

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28955 β€Ό

SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the First Name or Last Name input fields.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23047 β€Ό

Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the search input field of the search module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23037 β€Ό

Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".