πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-29719 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29716 β€Ό

IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.

πŸ“– Read

via "National Vulnerability Database".
❌ Omicron Phishing Scam Already Spotted in UK ❌

Omicron COVID-19 variant anxiety inspires new phishing scam offering fake NHS tests to steal data.

πŸ“– Read

via "Threat Post".
πŸ•΄ How Criminals Are Using Synthetic Identities for Fraud πŸ•΄

Organizations must improve their cybersecurity protocols to detect fraudulent identities and make sure they're safeguarding their consumers’ personal information.

πŸ“– Read

via "Dark Reading".
❌ Pandemic-Influenced Car Shopping: Just Use the Manufacturer API ❌

Jason Kent, hacker-in-residence at Cequence, found a way to exploit a Toyota API to get around the hassle of car shopping in the age of supply-chain woes.

πŸ“– Read

via "Threat Post".
πŸ•΄ IGI Cybersecurity Introduces CISO Team-as-a-Service πŸ•΄

Service gives customers access to a CISO-led team of practitioners with a variety of skills and expertise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ NSO Group Spyware Used to Breach US State Dept. Phones πŸ•΄

At least nine US State Department employee iPhones were targeted with sophisticated spyware developed by the Israeli firm NSO Group.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-23758 β€Ό

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44352 β€Ό

A Stack-based Buffer Overflow vlnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44347 β€Ό

SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44349 β€Ό

SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.class.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35346 β€Ό

tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function HevcSpsUnit::short_term_ref_pic_set(int) in hevc.cpp.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44348 β€Ό

SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23562 β€Ό

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35344 β€Ό

tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function BitStreamReader::getCurVal in bitStream.h.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ One-Third of Black Friday Shoppers Were Bots, Fake Users πŸ•΄

Fake traffic observed on Nov. 26 included malicious scrapers, sophisticated botnets, fake accounts, and click farms.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Who Is the Network Access Broker β€˜Babam’? β™ŸοΈ

Rarely do cybercriminal gangs that deploy ransomware gain the initial access to the target themselves. More commonly, that access is purchased from a cybercriminal broker who specializes in stealing remote access credentials -- such as usernames and passwords needed to remotely connect to the target's network. In this post we'll look at the clues left behind by "Babam," the handle chosen by a cybercriminal who has sold such access to ransomware groups on many occasions over the past few years.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2021-35415 β€Ό

A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43415 β€Ό

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35414 β€Ό

Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35413 β€Ό

A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.

πŸ“– Read

via "National Vulnerability Database".