πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38161 β€Ό

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23126 β€Ό

Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27836 β€Ό

An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37149 β€Ό

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23109 β€Ό

Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37148 β€Ό

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24743 β€Ό

An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43082 β€Ό

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24000 β€Ό

SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23679 β€Ό

Buffer overflow vulnerability in Renleilei1992 Linux_Network_Project 1.0, allows attackers to execute arbitrary code, via the password field.

πŸ“– Read

via "National Vulnerability Database".
❌ β€˜Tortilla’ Wraps Exchange Servers in ProxyShell Attacks ❌

The Microsoft Exchange ProxyShell vulnerabilities are being exploited yet again for ransomware, this time with Babuk from the new "Tortilla" threat actor.

πŸ“– Read

via "Threat Post".
🦿 Data and the policies that protect it: 4 essential plans to have in place 🦿

These four sample policies can help you protect your data by ensuring it's properly encrypted, stored safely, only accessible by certain people, and securely backed up.

πŸ“– Read

via "Tech Republic".
🦿 BlackMatter ransomware gang allegedly disbanding due to pressure from authorities 🦿

Operators of the ransomware-as-a-service group are claiming that the project is closed and that their entire infrastructure will be turned off.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Infosec and Business Alignment Lowers Breach Cost, Boosts Security πŸ•΄

As attacks and security budgets continue to rise, data shows the most secure organizations are the ones that strike a security-business balance.

πŸ“– Read

via "Dark Reading".
❌ Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign ❌

The banker, aka Metamorfo, is roaring back after Spanish police arrested more than a dozen gang members.

πŸ“– Read

via "Threat Post".
πŸ•΄ Where is Cloud Permissions Management headed? πŸ•΄

Cloud Permissions Management emerged as a standalone cloud security technology, but is quickly becoming part of a broader set of capabilities

πŸ“– Read

via "Dark Reading".
πŸ•΄ US Blacklists Israeli Firms NSO Group and Candiru πŸ•΄

The US Commerce Department has also added Russia's Positive Technologies and Singapore's Computer Security Initiative Consultancy.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-23624 β€Ό

This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23472 β€Ό

This affects all versions of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18263 β€Ό

PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23509 β€Ό

This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.

πŸ“– Read

via "National Vulnerability Database".