πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ WordPress Plugin Bug Lets Subscribers Wipe Sites ❌

The flaw, found in the Hashthemes Demo Importer plugin, allows any authenticated user to exsanguinate a vulnerable site, deleting nearly all database content and uploaded media.

πŸ“– Read

via "Threat Post".
πŸ•΄ Defenders Worry Orgs Are More Vulnerable Than Last Year πŸ•΄

Most IT and security leaders are confident their cybersecurity strategy is on the right track, but they still believe their organizations are as vulnerable as they were a year ago.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-25219 β€Ό

In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-1117 β€Ό

Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3901 β€Ό

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-1115 β€Ό

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs, where an attacker with local unprivileged system access may cause a NULL pointer dereference, which may lead to denial of service in a component beyond the vulnerable component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41191 β€Ό

Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allowed people who have someone's API URL to get product files without an API key. This issue is fixed in version 1.0.2. As a workaround, add `@require_apikey` in `BOT/lib/cogs/website.py` under the route for `/v1/products`.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-1116 β€Ό

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3903 β€Ό

vim is vulnerable to Heap-based Buffer Overflow

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21250 β€Ό

CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.

πŸ“– Read

via "National Vulnerability Database".
⚠ Apple ships Monterey with security updates, fixes 0-day in Watch and TV products, updates iDevices ⚠

A slew of security bulletins from Apple HQ, including 37 bugs listed as fixed in the initial public release of macOS Monterey.

πŸ“– Read

via "Naked Security".
πŸ•΄ HelpSystems Acquires Digital Guardian, Extends DLP Capabilities πŸ•΄

The acquisition strengthens HelpSystems’ data security portfolio with data loss prevention capabilities across the endpoint, network, and cloud.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-3906 β€Ό

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3904 β€Ό

grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19810 β€Ό

Zoom Call Recording 6.3.1 from ZOOM International is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.

πŸ“– Read

via "National Vulnerability Database".
❌ Grief Ransomware Targets NRA ❌

Grief, a ransomware group with ties to Russia-based Evil Corp, claims to have stolen data from the gun-rights group and has posted files on its dark web site. 

πŸ“– Read

via "Threat Post".
⚠ S3 Ep56: Cryptotrading rodent, ransomware hackback, and a Docusign phish [Podcast] ⚠

Latest episode - listen now! Serious security explained with personality in plain English.

πŸ“– Read

via "Naked Security".
πŸ•΄ You've Just Been Ransomed ... Now What? πŸ•΄

Six crucial steps executives and IT teams should be prepared to take immediately after a ransomware attack.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-22475 β€Ό

There is an Improper permission management vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22454 β€Ό

A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36990 β€Ό

There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

πŸ“– Read

via "National Vulnerability Database".