πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-42688 β€Ό

An Integer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B in the Accops HyWorks Windows Client prior to v 3.2.8.200 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42717 β€Ό

ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40578 β€Ό

Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38759 β€Ό

Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42683 β€Ό

A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42567 β€Ό

Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43963 β€Ό

An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write data in Couchbase Server were insecurely being stored in the metadata within sync documents written to the bucket. Users with read access could use these credentials to obtain write access. (This issue does not affect clusters where Sync Gateway is authenticated with X.509 client certificates. This issue also does not affect clusters where shared bucket access is not enabled on Sync Gateway.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42681 β€Ό

A Buffer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105. The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42682 β€Ό

An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 .The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43810 β€Ό

Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts. This issue is patched in version 4.0.12.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ New Financial Services Industry Report Reveals Major Gaps in Storage and Backup Security πŸ•΄

More than two-Thirds (69%) of respondents believe an attack on their storage & backup environment will have "significant" or "catastrophic" impact.

πŸ“– Read

via "Dark Reading".
πŸ“’ More than 90% of IT decision makers reuse passwords πŸ“’

Bitwarden survey also finds that half of IT professionals share their passwords with colleagues

πŸ“– Read

via "ITPro".
πŸ“’ Access brokers are making it easier for ransomware operators to attack businesses πŸ“’

A new business model has been uncovered that makes it much easier for attackers to gain access to business' networks

πŸ“– Read

via "ITPro".
πŸ“’ UK and Singapore align closer on digital trade πŸ“’

Three agreements have been signed which focus on facilitating digital trade, cyber security, and digital identities between the two nations

πŸ“– Read

via "ITPro".
πŸ“’ What is SSID? πŸ“’

We look at what SSID is and how it is used to connect devices to the internet

πŸ“– Read

via "ITPro".
πŸ“’ What is single sign-on (SSO)? πŸ“’

We explain how SSO works and why you need it

πŸ“– Read

via "ITPro".
πŸ“’ RNLI takes website offline after suspected cyber attack πŸ“’

The charity has not linked the incident to the recent pressure campaign from Britain First

πŸ“– Read

via "ITPro".
πŸ“’ How to boot Windows 11 in Safe Mode πŸ“’

Unless you’re a complete Windows 11 novice, you’ll have come across Safe Mode before - but what exactly is it, and how do you access it in Windows 11?

πŸ“– Read

via "ITPro".
πŸ“’ IT Pro 20/20: The problem with diversity in cyber security leadership πŸ“’

Why failing to address a shortage of women in senior roles puts businesses at risk - issue 23 is available to download now

πŸ“– Read

via "ITPro".
πŸ“’ Data protection policies and procedures πŸ“’

Why your company needs them, and what they should include

πŸ“– Read

via "ITPro".
πŸ“’ BitMart suspends withdrawals following hack πŸ“’

Hackers managed to get away with at least $150 million (Β£113 million) in cryptocurrencies

πŸ“– Read

via "ITPro".