πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-43038 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43039 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43037 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43042 β€Ό

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated attacker.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Crypto-exchange BitMart reports $150 million theft following hack πŸ—“οΈ

Security firm said attackers executed a β€˜transfer-out, swap, and wash’

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-4069 β€Ό

vim is vulnerable to Use After Free

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43469 β€Ό

VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.

πŸ“– Read

via "National Vulnerability Database".
⚠ Mozilla patches critical β€œBigSig” cryptographic bug: Here’s how to track it down and fix it ⚠

Mozilla's cryptographic code had a critical bug. Problem is that numerous apps are affected and may need patching individually.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-43471 β€Ό

In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Why the C-Suite Doesn't Need Access to All Corporate Data πŸ•΄

If zero trust is to work properly, then it must apply to everyone.

πŸ“– Read

via "Dark Reading".
🦿 How to lock a Zoom meeting to keep out unwanted guests 🦿

One good way to prevent unwelcome participants or late arrivals from joining your Zoom meetings is to lock those meetings. Here's a look at how it's done.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Critical vulnerabilities in open source forum software NodeBB could lead to RCE πŸ—“οΈ

Personal data, account access is at risk

πŸ“– Read

via "The Daily Swig".
⚠ Cryptocurrency startup fails to subtract before adding, loses $31m ⚠

Think of a number, any number. Take away 42. Add 42 back in. Then pretend you didn't take away 42. How much is left?

πŸ“– Read

via "Naked Security".
❌ Pegasus Spyware Infects U.S. State Department iPhones ❌

It's unknown who's behind the cyberattacks against at least nine employees' iPhones, who are all involved in Ugandan diplomacy.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Web security bugs discovered in CATIE assisted living framework πŸ—“οΈ

Care home communications tool conundrum

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-24931 β€Ό

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24938 β€Ό

The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24917 β€Ό

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25041 β€Ό

The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-24939 β€Ό

The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and rul_logout_url parameter before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24759 β€Ό

The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks

πŸ“– Read

via "National Vulnerability Database".