🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2021-3943

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.

📖 Read

via "National Vulnerability Database".
CVE-2021-40774

Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

📖 Read

via "National Vulnerability Database".
🛠 OpenStego Free Steganography Solution 0.8.1 🛠

OpenStego is a tool implemented in Java for generic steganography, with support for password-based encryption of the data. It supports plugins for various steganographic algorithms (currently, only Least Significant Bit algorithm is supported for images).

📖 Read

via "Packet Storm Security".
🛠 Hashcat Advanced Password Recovery 6.2.5 Binary Release 🛠

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the binary release.

📖 Read

via "Packet Storm Security".
🛠 Hashcat Advanced Password Recovery 6.2.5 Source Code 🛠

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the source code release.

📖 Read

via "Packet Storm Security".
🦿 Mozilla has released a new platform for privacy-focused email communications 🦿

When you don't want to give out your personal or work email address, but still need to sign up for an account, Mozilla might have an answer for you with Firefox Relay.

📖 Read

via "Tech Republic".
CVE-2021-23673

This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.

📖 Read

via "National Vulnerability Database".
CVE-2021-23732

This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system.

📖 Read

via "National Vulnerability Database".
CVE-2021-23718

The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly validate if the IP requested is private.

📖 Read

via "National Vulnerability Database".
CVE-2019-5640

Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

📖 Read

via "National Vulnerability Database".
Imunify360 Bug Leaves Linux Web Servers Open to Code Execution, Takeover

CloudLinux' security platform for Linux-based websites and web servers contains a high-severity PHP deserialization bug.

📖 Read

via "Threat Post".
Attackers Hijack Email Threads Using ProxyLogon/ProxyShell Flaws

Exploiting Microsoft Exchange ProxyLogon & ProxyShell vulnerabilities, attackers are malspamming replies in existing threads and slipping past malicious-email filters.

📖 Read

via "Threat Post".
🦿 Leaders agree that cybersecurity is a business risk, but are they acting on that belief? 🦿

Despite nearly unanimous agreement, there's still a lack of clarity on who is accountable for security incidents and whether previous security investments have paid off, a Gartner survey finds.

📖 Read

via "Tech Republic".
Online Merchants: Prevent Fraudsters from Becoming Holiday Grinches

Black Friday and Cyber Monday approach! Saryu Nayyar, CEO at Gurucul, discusses concerning statistics about skyrocketing online fraud during the festive season.

📖 Read

via "Threat Post".
🕴 10 Stocking Stuffers for Security Geeks 🕴

Check out our list of gifts with a big impact for hackers and other techie security professionals.

📖 Read

via "Dark Reading".
🔏 What's the Biggest Healthcare Security Threat for 2021 And Beyond? 🔏

We asked 21 cybersecurity experts and healthcare executives what the biggest security threat they're facing in 2021 and beyond is.

📖 Read

via "".
CVE-2021-42707

PLC Editor Versions 1.3.8 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

📖 Read

via "National Vulnerability Database".
CVE-2021-42705

PLC Editor Versions 1.3.8 and prior is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.

📖 Read

via "National Vulnerability Database".
CVE-2021-38448

The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

📖 Read

via "National Vulnerability Database".
CVE-2021-44143

A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution.

📖 Read

via "National Vulnerability Database".
🦿 GoDaddy security breach impacts more than 1 million WordPress users 🦿

The hosting company has revealed a security incident that exposed the email addresses and customer numbers of 1.2 million Managed WordPress customers.

📖 Read

via "Tech Republic".