πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-24745 β€Ό

The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ UK Department for Transport caught inadvertently serving pornographic content to site visitors πŸ—“οΈ

β€˜The page has since been permanently deleted’, a government spokesperson told The Daily Swig

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-43698 β€Ό

An unspecified version of phpWhois is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET['query'] then there is a XSS vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Interpol arrests 1,000 suspects, seizes $27m in crackdown on cybercrime πŸ—“οΈ

Worldwide law enforcement operation targets online crime surge

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Paving the Road to Zero Trust With Adaptive Authentication πŸ•΄

A gradual transition to a world beyond passwords predisposes zero-trust projects to success.

πŸ“– Read

via "Dark Reading".
πŸ•΄ NanoLock Security and Waterfall Security Partner to Deliver OT Security for Industrial and Energy Applications πŸ•΄

The solution combines NanoLock’s device-level, zero-trust protection with Waterfall’s hardware-enforced IT/OT perimeter protection to provide a powerful OT security solution that mitigates cyber events from both IT and OT networks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-43696 β€Ό

An unspecified version of twmap is affected by a Cross Site Scripting (XSS) vulnerability. In file list.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST then there is a XSS vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43695 β€Ό

An unspecified version of issabelPBX is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST without sanitization, then there is a XSS vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43697 β€Ό

An unspecified version of Workerman-ThinkPHP-Redis is affected by a Cross Site Scripting (XSS) vulnerability. In file Controller.class.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET{C('VAR_JSONP_HANDLER')] then there is a XSS vulnerability.

πŸ“– Read

via "National Vulnerability Database".
🦿 WFH security: How to protect your remote endpoints from vulnerabilities 🦿

Many organizations lack an effective patch management program, especially when it comes to patching remote systems, says Action1.

πŸ“– Read

via "Tech Republic".
⚠ Cloud Security: Don’t wait until your next bill to find out about an attack! ⚠

Cloud security is the best sort of altruism: you need to do it to protect yourself, but you help to protect everyone else at the same time.

πŸ“– Read

via "Naked Security".
❌ Shape-Shifting β€˜Tardigrade’ Malware Hits Vaccine Makers ❌

Some security researchers say it’s actually Cobalt Strike and not a SmokeLoader variant, but BioBright says in-depth testing shows it’s for real a scary morphic malware that changes its parts and recompiles itself.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Italian police crack down on fake Covid-19 vaccination passes πŸ—“οΈ

Underground trade conducted over Telegram

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-3802 β€Ό

A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43691 β€Ό

An unspecified version of tripexpress is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39995 β€Ό

Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi contains an out-of-bounds read vulnerability that could lead to a denial of service. Affected product versions include: eCNS280_TD V100R005C10; eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43692 β€Ό

An unspecified version of youtube-php-mirroring is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43693 β€Ό

vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.

πŸ“– Read

via "National Vulnerability Database".
❌ Unpatched Windows Zero-Day Allows Privileged File Access ❌

A temporary fix has been issued for CVE-2021-24084, which can be exploited using the LPE exploitation approach for the HiveNightmare/SeriousSAM bug.

πŸ“– Read

via "Threat Post".
πŸ›  OpenStego Free Steganography Solution 0.8.2 πŸ› 

OpenStego is a tool implemented in Java for generic steganography, with support for password-based encryption of the data. It supports plugins for various steganographic algorithms (currently, only Least Significant Bit algorithm is supported for images).

πŸ“– Read

via "Packet Storm Security".
❌ ScarCruft APT Mounts Desktop/Mobile Double-Pronged Spy Attacks ❌

The North Korea-linked group is deploying the Chinotto spyware backdoor against dissidents, journalists and other politically relevant individuals in South Korea.

πŸ“– Read

via "Threat Post".