πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ New Application Security Toolkit Uncovers Dependency Confusion Attacks πŸ•΄

The Dependency Combobulator is an open source Python-based toolkit that helps developers discover malicious software components that may have accidentally been added to their projects.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-40873 β€Ό

An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40871 β€Ό

An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a OPC/UA client. The client process may crash unexpectedly because of a wrong type cast, and must be restarted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40872 β€Ό

An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type cast, and must be restarted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33816 β€Ό

The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33618 β€Ό

Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26558 β€Ό

Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versions prior to 5.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25980 β€Ό

In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular, are vulnerable to Host Header Injection. By luring a victim application-user to click on a link, an unauthenticated attacker can use the Ò€œforgot passwordҀ� functionality to reset the victimÒ€ℒs password and successfully take over their account.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Should Our Security Controls Be More Like North Korea or Norway? πŸ•΄

When the drive for additional visibility and awareness is led by the business rather than just a SOC team, both the business and security can benefit.

πŸ“– Read

via "Dark Reading".
❌ Tiny Font Size Fools Email Filters in BEC Phishing ❌

The One Font BEC campaign targets Microsoft 365 users and uses sophisticated obfuscation tactics to slip past security protections to harvest credentials.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Dependency Combobulator offers defense against namespace confusion attacks πŸ—“οΈ

Toolkit β€˜tackles common scenarios’ and can evolve to detect emerging attack variants

πŸ“– Read

via "The Daily Swig".
⚠ Patch Tuesday updates the Win 7 updater… for at most 1 more year of updates ⚠

The clock stopped long ago on Windows 7, except for those who paid for overtime. But there won't be any double overtime!

πŸ“– Read

via "Naked Security".
🦿 How cybercriminals use bait attacks to gather info about their intended victims 🦿

With a bait attack, criminals try to obtain the necessary details to plan future attacks against their targets, says Barracuda.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Palo Alto GlobalProtect users urged to patch against critical vulnerability πŸ—“οΈ

Details withheld about dangerous threat as orgs given one-month patching window

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-43350 β€Ό

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Zero tolerance: How infosec’s online β€˜cancel culture’ is stunting industry growth πŸ—“οΈ

Fear of Twitter fallout is stopping vital information from being shared Social media backlash and online squabbling is stopping the information security industry from learning from its mistakes, Black

πŸ“– Read

via "The Daily Swig".
🦿 This pre-Black Friday sale lets you save an extra 15% off cybersecurity certification training courses 🦿

Receive over 100 hours of expert instruction on globally recognized cybersecurity skills that will help you become an in-demand IT professional.

πŸ“– Read

via "Tech Republic".
🦿 How to easily transfer files between computers with croc 🦿

If you're looking for an easy command-line tool to transfer files between systems on the same LAN, Jack Wallen believes croc is the tool for the job.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ GoCD bug chain provides second springboard to supply chain attacks πŸ—“οΈ

Follow-up to recent GoCD disclosure provides additional path to infiltrating build environments

πŸ“– Read

via "The Daily Swig".
⚠ S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust [Podcast] ⚠

Latest epsiode - listen now!

πŸ“– Read

via "Naked Security".
πŸ•΄ Third-Party Software Risks Grow, but So Do Solutions πŸ•΄

Enterprises are more dependent than ever on open source software and need to manage the risk posed by vulnerabilities in components and third-party vendors.

πŸ“– Read

via "Dark Reading".