πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-4019 β€Ό

vim is vulnerable to Heap-based Buffer Overflow

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34599 β€Ό

Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server provides a valid and trusted HTTPS certificate. Since the certificate of the server to which the connection is made is not properly verified, the server connection is vulnerable to a man-in-the-middle attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4018 β€Ό

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
❌ Widespread β€˜Smishing’ Campaign Defrauds Iranian Android Users ❌

Attackers use socially engineered SMS messages and malware to compromise tens of thousands of devices and drain user bank accounts.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-4017 β€Ό

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3989 β€Ό

showdoc is vulnerable to URL Redirection to Untrusted Site

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3990 β€Ό

showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3964 β€Ό

elgg is vulnerable to Authorization Bypass Through User-Controlled Key

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3983 β€Ό

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3984 β€Ό

vim is vulnerable to Heap-based Buffer Overflow

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3992 β€Ό

kimai2 is vulnerable to Improper Access Control

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4015 β€Ό

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3985 β€Ό

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3994 β€Ό

django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3993 β€Ό

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32592 β€Ό

An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search path.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Sixth member of notorious SIM-swapping cybercrime gang sentenced πŸ—“οΈ

US crime syndicate β€˜The Community’ stole millions of dollars’ worth of cryptocurrency

πŸ“– Read

via "The Daily Swig".
⚠ Clearview AI face-matching service set to be fined over $20m ⚠

Scraping data for a facial recognition service? "That's unlawful", concluded both the British and the Australians.

πŸ“– Read

via "Naked Security".
πŸ•΄ The Cyber Threats Facing Retailers This Holiday Shopping Season πŸ•΄

With supply chain delays and an online shopping boom, attacks will come from multiple angles.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-43690 β€Ό

YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will terminate the script and print a message which have values from the socket_read.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44280 β€Ό

attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.

πŸ“– Read

via "National Vulnerability Database".