πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-44045 β€Ό

An out-of-bounds write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DGN files. Crafted data in a DGN file and lack of proper validation for the XFAT sectors count can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43035 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote code execution was possible, leading to full access to the postgres user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43041 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43036 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43043 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43033 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server) being passed to system calls.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43040 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43044 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43034 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43038 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43039 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43037 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43042 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated attacker.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Crypto-exchange BitMart reports $150 million theft following hack πŸ—“οΈ

Security firm said attackers executed a β€˜transfer-out, swap, and wash’

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-4069 β€Ό

vim is vulnerable to Use After Free

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43469 β€Ό

VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.

πŸ“– Read

via "National Vulnerability Database".
⚠ Mozilla patches critical β€œBigSig” cryptographic bug: Here’s how to track it down and fix it ⚠

Mozilla's cryptographic code had a critical bug. Problem is that numerous apps are affected and may need patching individually.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-43471 β€Ό

In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Why the C-Suite Doesn't Need Access to All Corporate Data πŸ•΄

If zero trust is to work properly, then it must apply to everyone.

πŸ“– Read

via "Dark Reading".
🦿 How to lock a Zoom meeting to keep out unwanted guests 🦿

One good way to prevent unwelcome participants or late arrivals from joining your Zoom meetings is to lock those meetings. Here's a look at how it's done.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Critical vulnerabilities in open source forum software NodeBB could lead to RCE πŸ—“οΈ

Personal data, account access is at risk

πŸ“– Read

via "The Daily Swig".