πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ DDoS attacks are crippling UK VoIP operators πŸ“’

Businesses and emergency services are among customers hit by outages at VoIP firms

πŸ“– Read

via "ITPro".
πŸ“’ Critical macOS vulnerability found to bypass SIP restrictions πŸ“’

The flaw lies in how the OS handles software packages and post-installation scripts

πŸ“– Read

via "ITPro".
πŸ“’ Australian Federal Police plots "aggressive" cyber division following law change πŸ“’

New powers allow law enforcement to launch disruptive operations and collect data on suspected criminals

πŸ“– Read

via "ITPro".
πŸ“’ Luxury hotel chain hit twice by hackers after reneging on ransomware payment πŸ“’

The group claims to have information belonging to millions of customers who stayed at Centara hotels and resorts between 2003 and 2021

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft resellers warned of Nobelium attacks on IT supply chain πŸ“’

Microsoft believes that 22,868 attacks have been conducted against 609 partners since July

πŸ“– Read

via "ITPro".
πŸ“’ UK gov must act now to regulate Facebook, says whistleblower πŸ“’

Frances Haugen told members of the Online Safety Bill committee that the social network "is closing the door on us being able to act”

πŸ“– Read

via "ITPro".
πŸ“’ Critical vulnerability discovered in popular CI/CD framework πŸ“’

Flaw in GoCD software delivery pipeline thought to have affected a host of NGOs and Fortune 500 companies

πŸ“– Read

via "ITPro".
πŸ“’ Ransomware gang claims to have hacked the NRA πŸ“’

β€œGrief" gang says it has already leaked some of its stolen data to the dark web

πŸ“– Read

via "ITPro".
β€Ό CVE-2020-25912 β€Ό

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25911 β€Ό

A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33259 β€Ό

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ β€˜Trojan Source’ Bug Threatens the Security of All Code β™ŸοΈ

Virtually all compilers -- programs that transform human-readable source code into computer-executable machine code -- are vulnerable to an insidious attack in which an adversary can introduce targeted vulnerabilities into any software without being detected, new research released today warns. The vulnerability disclosure was coordinated with multiple organizations, some of whom are now releasing updates to address the security weakness.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2021-24789 β€Ό

The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-25019 β€Ό

The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24793 β€Ό

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24799 β€Ό

The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24742 β€Ό

The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24570 β€Ό

The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24624 β€Ό

The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24682 β€Ό

The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24794 β€Ό

The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.

πŸ“– Read

via "National Vulnerability Database".