πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Are You Planning for the Quantum, Transhumanist Threat? πŸ•΄

Breaking encryption in a day and hacking without visible devices are two threats that could become a reality in the next decade and beyond, experts say.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Fixes Exchange Server Zero-Day πŸ•΄

November security update contains patches for 55 bugs β€” including six zero-days across various products.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-43575 β€Ό

** DISPUTED ** KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this because it is not the responsibility of the ETS to securely store cryptographic key material when it is not being exported.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35488 β€Ό

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35489 β€Ό

Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.cgi. The malicious payload would be triggered every time an authenticated user browses the page containing it.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37157 β€Ό

An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37158 β€Ό

An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42292 β€Ό

Microsoft Excel Security Feature Bypass Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41366 β€Ό

Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42304 β€Ό

Azure RTOS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42302, CVE-2021-42303.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42288 β€Ό

Windows Hello Security Feature Bypass Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42279 β€Ό

Chakra Scripting Engine Memory Corruption Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41367 β€Ό

NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41370, CVE-2021-42283.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41373 β€Ό

FSLogix Information Disclosure Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41356 β€Ό

Windows Denial of Service Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42323 β€Ό

Azure RTOS Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-26444, CVE-2021-42301.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31853 β€Ό

DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Apache Storm maintainers patch two pre-auth RCE vulnerabilities πŸ—“οΈ

High-risk issues were discovered by GitHub’s in-house security team

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-34598 β€Ό

In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39474 β€Ό

Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker with privileges and network access through the ping.cmd component to execute commands on the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43136 β€Ό

An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.

πŸ“– Read

via "National Vulnerability Database".