πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ β€˜Appalling’ Riot Games Job Fraud Takes Aim at Wallets ❌

Scammers are using fake job listings to empty the wallets of young, hopeful victims looking to break into the gaming industry.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-38917 β€Ό

IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system memory through a series of carefully crafted service procedures. IBM X-Force ID: 210018.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31745 β€Ό

Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36911 β€Ό

Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37935 β€Ό

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38937 β€Ό

IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a specially crafted IBMi Hypervisor call. IBM X-Force ID: 210894.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37934 β€Ό

Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for brute-force password guessing.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43813 β€Ό

Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains a directory traversal vulnerability for fully lowercase or fully uppercase .md files. The vulnerability is limited in scope, and only allows access to files with the extension .md to authenticated users only. Grafana Cloud instances have not been affected by the vulnerability. Users should upgrade to patched versions 8.3.2 or 7.5.12. For users who cannot upgrade, running a reverse proxy in front of Grafana that normalizes the PATH of the request will mitigate the vulnerability. The proxy will have to also be able to handle url encoded paths. Alternatively, for fully lowercase or fully uppercase .md files, users can block /api/plugins/.*/markdown/.* without losing any functionality beyond inlined plugin help text.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29214 β€Ό

A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerability is limited to SSMC. Note: The arrays being managed are not impacted by this vulnerability. This vulnerability impacts SSMC versions 3.4 GA to 3.8.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31746 β€Ό

Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
❌ Next-Gen Maldocs & How to Solve the Human Vulnerability ❌

Malicious email attachments with macros are one of the most common ways hackers get in through the door. Huntress security researcher John Hammond discusses how threat hunters can fight back.

πŸ“– Read

via "Threat Post".
🦿 Study: Most phishing pages are abandoned or disappear in a matter of days 🦿

Research from Kaspersky finds that a quarter of phishing sites are gone within 13 hours β€” how in the world can we catch and stop cyber criminals that move so quickly?

πŸ“– Read

via "Tech Republic".
🦿 Hackers reported 21% more vulnerabilities in 2021 than in 2020 🦿

HackerOne reports that hackers are reporting more bugs and earning bigger bounties, but is an increase in testing or an increase in software vulnerabilities the cause of the jump?

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-4089 β€Ό

snipe-it is vulnerable to Improper Access Control

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31747 β€Ό

Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23639 β€Ό

The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27983 β€Ό

Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23663 β€Ό

All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23700 β€Ό

All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23463 β€Ό

The package com.h2database:h2 from 0 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23561 β€Ό

All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.

πŸ“– Read

via "National Vulnerability Database".