πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-26108 β€Ό

A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.

πŸ“– Read

via "National Vulnerability Database".
🦿 Telemedicine: Doctors and patients are both worried about privacy and data security 🦿

Kaspersky survey finds 34% of telehealth providers admit to a wrong diagnosis due to poor video or photo quality.

πŸ“– Read

via "Tech Republic".
⚠ Firefox update brings a whole new sort of security sandbox ⚠

Firefox 95.0 is out, with the usual security fixes... plus some funky new ones.

πŸ“– Read

via "Naked Security".
🦿 Cybersecurity: Organizations face key obstacles in adopting zero trust 🦿

Security pros surveyed by One Identity cited a lack of clarity, other priorities and a lack of resources as bumps on the road to Zero Trust.

πŸ“– Read

via "Tech Republic".
πŸ›  ETS5 Password Recovery Tool πŸ› 

ETS Password Recovery Tool allows you to recover passwords for an ETS5 project. This is due to a significant design flaw as ETS5 uses a hard-coded password and salt to encrypt the project information.

πŸ“– Read

via "Packet Storm Security".
πŸ—“οΈ US Department of Homeland Security heeds calls for tougher transport cybersecurity rules πŸ—“οΈ

TSA issues mandatory requirements for β€˜high-risk’ rail infrastructure

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-41450 β€Ό

An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25521 β€Ό

Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25524 β€Ό

Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37097 β€Ό

There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25513 β€Ό

An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37069 β€Ό

There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25512 β€Ό

An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37050 β€Ό

There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37054 β€Ό

There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25518 β€Ό

An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25511 β€Ό

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25510 β€Ό

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37037 β€Ό

There is an Invalid address access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42110 β€Ό

An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40860 β€Ό

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

πŸ“– Read

via "National Vulnerability Database".