β Firefox update brings a whole new sort of security sandbox β
π Read
via "Naked Security".
Firefox 95.0 is out, with the usual security fixes... plus some funky new ones.π Read
via "Naked Security".
Naked Security
Firefox update brings a whole new sort of security sandbox
Firefox 95.0 is out, with the usual security fixes⦠plus some funky new ones.
π¦Ώ Cybersecurity: Organizations face key obstacles in adopting zero trust π¦Ώ
π Read
via "Tech Republic".
Security pros surveyed by One Identity cited a lack of clarity, other priorities and a lack of resources as bumps on the road to Zero Trust.π Read
via "Tech Republic".
TechRepublic
Cybersecurity: Organizations face key obstacles in adopting zero trust
Security pros surveyed by One Identity cited a lack of clarity, other priorities and a lack of resources as bumps on the road to zero trust.
π ETS5 Password Recovery Tool π
π Read
via "Packet Storm Security".
ETS Password Recovery Tool allows you to recover passwords for an ETS5 project. This is due to a significant design flaw as ETS5 uses a hard-coded password and salt to encrypt the project information.π Read
via "Packet Storm Security".
Packetstormsecurity
ETS5 Password Recovery Tool β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
ποΈ US Department of Homeland Security heeds calls for tougher transport cybersecurity rules ποΈ
π Read
via "The Daily Swig".
TSA issues mandatory requirements for βhigh-riskβ rail infrastructureπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
US Department of Homeland Security heeds calls for tougher transport cybersecurity rules
TSA issues mandatory requirements for βhigh-riskβ rail infrastructure
βΌ CVE-2021-41450 βΌ
π Read
via "National Vulnerability Database".
An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25521 βΌ
π Read
via "National Vulnerability Database".
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25524 βΌ
π Read
via "National Vulnerability Database".
Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37097 βΌ
π Read
via "National Vulnerability Database".
There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25513 βΌ
π Read
via "National Vulnerability Database".
An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37069 βΌ
π Read
via "National Vulnerability Database".
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25512 βΌ
π Read
via "National Vulnerability Database".
An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37050 βΌ
π Read
via "National Vulnerability Database".
There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37054 βΌ
π Read
via "National Vulnerability Database".
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25518 βΌ
π Read
via "National Vulnerability Database".
An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25511 βΌ
π Read
via "National Vulnerability Database".
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25510 βΌ
π Read
via "National Vulnerability Database".
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37037 βΌ
π Read
via "National Vulnerability Database".
There is an Invalid address access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart.π Read
via "National Vulnerability Database".
βΌ CVE-2021-42110 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40860 βΌ
π Read
via "National Vulnerability Database".
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25514 βΌ
π Read
via "National Vulnerability Database".
An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25515 βΌ
π Read
via "National Vulnerability Database".
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.π Read
via "National Vulnerability Database".