βΌ CVE-2021-29993 βΌ
π Read
via "National Vulnerability Database".
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38492 βΌ
π Read
via "National Vulnerability Database".
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.π Read
via "National Vulnerability Database".
π΄ Simulation Game Teaches Non-Security Staff How to Handle a Cyber Crisis π΄
π Read
via "Dark Reading".
In this card-based game from Kaspersky, players work through a cyberattack scenario and learn how each decision they make has consequences.π Read
via "Dark Reading".
Dark Reading
Simulation Game Teaches Non-Security Staff How to Handle a Cyber Crisis
In this card-based game from Kaspersky, players work through a cyberattack scenario and learn how each decision they make has consequences.
βΌ CVE-2021-40849 βΌ
π Read
via "National Vulnerability Database".
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40848 βΌ
π Read
via "National Vulnerability Database".
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.π Read
via "National Vulnerability Database".
βΌ CVE-2021-33209 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Fimer Aurora Vision before 2.97.10. The response to a failed login attempt discloses whether the username or password is wrong, helping an attacker to enumerate usernames. This can make a brute-force attack easier.π Read
via "National Vulnerability Database".
βΌ CVE-2021-33210 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information without authentication by reading the response of APIs from a kiosk view of a plant.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36192 βΌ
π Read
via "National Vulnerability Database".
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS.π Read
via "National Vulnerability Database".
β Report: BlackMatter Ransomware Gang Goes Dark, Again β
π Read
via "Threat Post".
The former DarkSide cybercriminal group will shut down due to increased pressure from authorities, who may have nabbed a key team member.π Read
via "Threat Post".
Threat Post
Report: BlackMatter Ransomware Gang Goes Dark, Again
The former DarkSide cybercriminal group will shut down due to increased pressure from authorities, who may have nabbed a key team member.
π¦Ώ Ransomware gangs leaking sensitive financial information to extort organizations π¦Ώ
π Read
via "Tech Republic".
Attackers will threaten to release confidential data that could affect a company's stock price to pressure them to pay the ransom, says the FBI.π Read
via "Tech Republic".
TechRepublic
Ransomware gangs leaking sensitive financial information to extort organizations
Attackers will threaten to release confidential data that could affect a company's stock price to pressure them to pay the ransom, says the FBI.
π¦Ώ Digital natives more likely to fall for phishing attacks at work than their Gen X and Boomer colleagues π¦Ώ
π Read
via "Tech Republic".
SailPoint survey finds that younger workers also are more likely to use company email addresses for online shopping and subscriptions.π Read
via "Tech Republic".
TechRepublic
Digital natives more likely to fall for phishing attacks at work than their Gen X and Boomer colleagues
SailPoint survey finds that younger workers also are more likely to use company email addresses for online shopping and subscriptions.
π¦Ώ Rootkits: Expensive to build, cheap to rent π¦Ώ
π Read
via "Tech Republic".
Positive Technology analysts found ready-made malware for any budget as well as the option to have a custom-build rootkit on Dark Web forums.π Read
via "Tech Republic".
TechRepublic
Rootkits: Expensive to build, cheap to rent
Positive Technology analysts found ready-made malware for any budget as well as the option to have a custom-build rootkit on Dark Web forums.
ποΈ RCE vulnerability found in Sitecore enterprise CMS software ποΈ
π Read
via "The Daily Swig".
Vendor update is available nowπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
RCE vulnerability found in Sitecore enterprise CMS software
Vendor update is available now
π΄ Risk Quantification: A Powerful Tool in Your Cyberthreat Defense Arsenal π΄
π Read
via "Dark Reading".
Three ways that understanding your cyber-risk in real dollars can help your organization survive the threat of ransomware and other attacks.π Read
via "Dark Reading".
Dark Reading
Risk Quantification: A Powerful Tool in Your Cyberthreat Defense Arsenal
Three ways that understanding your cyber-risk in real dollars can help your organization survive the threat of ransomware and other attacks.
βΌ CVE-2021-36697 βΌ
π Read
via "National Vulnerability Database".
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36698 βΌ
π Read
via "National Vulnerability Database".
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.π Read
via "National Vulnerability Database".
π΄ Valtix Delivers Free Cloud Security for Departmental, Development, and Test Applications π΄
π Read
via "Dark Reading".
Company aims to make cloud network security more accessible to all organizations.π Read
via "Dark Reading".
Dark Reading
Valtix Delivers Free Cloud Security for Departmental, Development, and Test Applications
Company aims to make cloud network security more accessible to all organizations.
ποΈ Dangerous uXSS bug in Google Chromeβs βNew Tabβ page bypassed security features ποΈ
π Read
via "The Daily Swig".
βChromeβs NTP only has a really weak CSP that doesnβt mitigate XSSβπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Dangerous XSS bug in Google Chromeβs βNew Tabβ page bypassed security features
βChromeβs New Tab page only has a really weak CSP that doesnβt mitigate XSSβ
π¦Ώ Report: More than half of organizations do not effectively defend against cyberattacks π¦Ώ
π Read
via "Tech Republic".
Accenture's State of Cyber Resilience study also revealed key traits of cyber resilient leaders. The report found an average of 270 attacks per year per company.π Read
via "Tech Republic".
TechRepublic
Report: More than half of organizations do not effectively defend against cyberattacks
Accenture's State of Cyber Resilience study also revealed key traits of cyber resilient leaders. The report found an average of 270 attacks per year per company.
βΌ CVE-2021-43130 βΌ
π Read
via "National Vulnerability Database".
An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43324 βΌ
π Read
via "National Vulnerability Database".
LibreNMS through 21.10.2 allows XSS via a widget title.π Read
via "National Vulnerability Database".