πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Infosec and Business Alignment Lowers Breach Cost, Boosts Security πŸ•΄

As attacks and security budgets continue to rise, data shows the most secure organizations are the ones that strike a security-business balance.

πŸ“– Read

via "Dark Reading".
❌ Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign ❌

The banker, aka Metamorfo, is roaring back after Spanish police arrested more than a dozen gang members.

πŸ“– Read

via "Threat Post".
πŸ•΄ Where is Cloud Permissions Management headed? πŸ•΄

Cloud Permissions Management emerged as a standalone cloud security technology, but is quickly becoming part of a broader set of capabilities

πŸ“– Read

via "Dark Reading".
πŸ•΄ US Blacklists Israeli Firms NSO Group and Candiru πŸ•΄

The US Commerce Department has also added Russia's Positive Technologies and Singapore's Computer Security Initiative Consultancy.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-23624 β€Ό

This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23472 β€Ό

This affects all versions of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18263 β€Ό

PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23509 β€Ό

This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18259 β€Ό

ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Post title or Post content fields.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23807 β€Ό

This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18262 β€Ό

ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43140 β€Ό

SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18261 β€Ό

An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23820 β€Ό

This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41134 β€Ό

nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) issue exists within the Jupyter-owned nbdime project. It appears that when reading the file name and path from disk, the extension does not sanitize the string it constructs before returning it to be displayed. The diffNotebookCheckpoint function within nbdime causes this issue. When attempting to display the name of the local notebook (diffNotebookCheckpoint), nbdime appears to simply append .ipynb to the name of the input file. The NbdimeWidget is then created, and the base string is passed through to the request API function. From there, the frontend simply renders the HTML tag and anything along with it. Users are advised to patch to the most recent version of the affected product.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43141 β€Ό

Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41174 β€Ό

Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }} ex: {{constructor.constructor(ΓƒΒ’Γ’β€šΒ¬Γ‹Ε“alert(1)ΓƒΒ’Γ’β€šΒ¬Γ’β€žΒ’)()}}. When the user follows the link and the page renders, the login button will contain the original link with a query parameter to force a redirect to the login page. The URL is not validated and the AngularJS rendering engine will execute the JavaScript expression contained in the URL. Users are advised to upgrade as soon as possible. If for some reason you cannot upgrade, you can use a reverse proxy or similar to block access to block the literal string {{ in the path.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23784 β€Ό

This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cloud Data Security Startup Launches πŸ•΄

TrustLogix aims to streamline and simplify data governance in the cloud.

πŸ“– Read

via "Dark Reading".
🦿 Cisco Talos reports new variant of Babuk ransomware targeting Exchange servers 🦿

A new bad actor called Tortilla is running the campaign, and most affected users are in the U.S.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 5 MITRE ATT&CK Tactics Most Frequently Detected by Cisco Secure Firewalls πŸ•΄

Cisco Security examines the most frequently encountered MITRE ATT&CK tactics and techniques.

πŸ“– Read

via "Dark Reading".