πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-43683 β€Ό

pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will terminate the script and print the message which has $_REQUEST['hash'].

πŸ“– Read

via "National Vulnerability Database".
πŸ” Five Health Providers Held Accountable for Violating HIPAA Right of Access πŸ”

OCR has shown that its serious about patients being able to access their healthcare records – recently levied penalties serve as a reminder for organizations to know where PHI is at all times.

πŸ“– Read

via "".
β™ŸοΈ Ubiquiti Developer Charged With Extortion, Causing 2020 β€œBreach” β™ŸοΈ

In January 2021, technology vendor Ubiquiti Inc. [NYSE:UI] disclosed that a breach at a third party cloud provider had exposed customer account credentials. In March, a Ubiquiti employee warned that the company had drastically understated the scope of the incident, and that the third-party cloud provider claim was a fabrication. On Wednesday, a former Ubiquiti developer was arrested and charged with stealing data and trying to extort his employer while pretending to be a whistleblower.

πŸ“– Read

via "Krebs on Security".
πŸ›  I2P 1.6.1 πŸ› 

I2P is an anonymizing network, offering a simple layer that identity-sensitive applications can use to securely communicate. All data is wrapped with several layers of encryption, and the network is both distributed and dynamic, with no trusted parties. This is the source code release version.

πŸ“– Read

via "Packet Storm Security".
πŸ—“οΈ Ransomware groups increasingly using data leak threats to pile pressure on victims πŸ—“οΈ

Nearly one in three victims succumb to extortion, estimates Group-IB

πŸ“– Read

via "The Daily Swig".
πŸ•΄ When Will a Cloud Infrastructure Heavyweight Launch a SASE? πŸ•΄

There's been a veritable gold rush of security vendors getting into secure access service edge. Now will any of the major IaaS vendors enter the market? Rik Turner makes the case.

πŸ“– Read

via "Dark Reading".
⚠ IoT devices must β€œprotect consumers from cyberharm”, says UK government ⚠

"Must be at least THIS tall to go on ride" seems to be the starting point. Too little, too late? Or better than nothing?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-23260 β€Ό

Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23262 β€Ό

Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23263 β€Ό

Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23258 β€Ό

Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23259 β€Ό

Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23261 β€Ό

Authenticated administrators may override the system configuration file and cause a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43679 β€Ό

ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23264 β€Ό

Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Key Characteristics of Malicious Domains: Report πŸ•΄

Newer top-level domains and certain hosting providers are frequent sources of malicious content, while newly registered domains and free SSL certificates are not any more likely than average to be risky, new research shows.

πŸ“– Read

via "Dark Reading".
❌ AT&T Takes Steps to Mitigate Botnet Found Inside Its Network  ❌

AT&T is battling a modular malware called EwDoor on 5,700 VoIP servers, but it could have a larger wildcard certificate problem.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-3944 β€Ό

bookstack is vulnerable to Cross-Site Request Forgery (CSRF)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-20106 β€Ό

The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-20105 β€Ό

The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues

πŸ“– Read

via "National Vulnerability Database".