๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2021-24853 โ€ผ

The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42379 (busybox) โ€ผ

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-12905 โ€ผ

Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004403 may lead to arbitrary information disclosure.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-25982 โ€ผ

In Factor (App Framework & Headless CMS) forum plugin, versions 1.3.5 to 1.8.30, are vulnerable to reflected Cross-Site Scripting (XSS) at the รขโ‚ฌล“searchรขโ‚ฌ๏ฟฝ parameter in the URL. An unauthenticated attacker can execute malicious JavaScript code and steal the session cookies.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42703 (webaccess_hmi_designer) โ€ผ

This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the userรขโ‚ฌโ„ขs cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-12903 โ€ผ

Out of Bounds Write and Read in AMD Graphics Driver for Windows 10 in Escape 0x6002d03 may lead to escalation of privilege or denial of service.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42385 (busybox) โ€ผ

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-25985 โ€ผ

In Factor (App Framework & Headless CMS) v1.0.4 to v1.8.30, improperly invalidate a userรขโ‚ฌโ„ขs session even after the user logs out of the application. In addition, user sessions are stored in the browserรขโ‚ฌโ„ขs local storage, which by default does not have an expiration time. This makes it possible for an attacker to steal and reuse the cookies using techniques such as XSS attacks, followed by a local account takeover.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-29861 โ€ผ

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensitive information. IBM X-Force ID: 206085.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-26323 โ€ผ

Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24802 โ€ผ

The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-41266 โ€ผ

Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are subject to an authentication bypass issue in the Operator Console when an external IDP is enabled. All users on release v0.12.2 and before are affected and are advised to update to 0.12.3 or newer. Users unable to upgrade should add automountServiceAccountToken: false to the operator-console deployment in Kubernetes so no service account token will get mounted inside the pod, then disable the external identity provider authentication by unset the CONSOLE_IDP_URL, CONSOLE_IDP_CLIENT_ID, CONSOLE_IDP_SECRET and CONSOLE_IDP_CALLBACK environment variable and instead use the Kubernetes service account token.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42373 โ€ผ

A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42721 โ€ผ

Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42374 โ€ผ

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-12902 โ€ผ

Arbitrary Decrement Privilege Escalation in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-42377 โ€ผ

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  Emotet malware: โ€œThe report of my death was an exaggerationโ€ โš 

"Old malware rarely dies." The best way to predict the future is to look at the past... if it worked before, it will probably work again.

๐Ÿ“– Read

via "Naked Security".
โš  The self-driving smart suitcaseโ€ฆ that the person behind you can hijack! โš 

Apparently, we need a self-driving IoT Bluetooth robot suitcase. Who knew?

๐Ÿ“– Read

via "Naked Security".
๐Ÿฆฟ Your weak passwords can be cracked in less than a second ๐Ÿฆฟ

Easy-to-crack phrases "123456," "123456789," "12345," "qwerty" and "password" are the five most common passwords, says NordPass.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿฆฟ How to protect your organization from ransomware attacks during the holiday season ๐Ÿฆฟ

A quarter of security pros polled by Cybereason said they lack a plan to deal with a ransomware attack during a weekend or holiday.

๐Ÿ“– Read

via "Tech Republic".