πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-27984 β€Ό

In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41242 β€Ό

OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and write files anywhere on the target system. The attack could be used to write files anywhere in the web root folder or outside, depending on the configuration of the system and the properly configured permission of the application server user. The attack requires an OpenOlat user account, an enabled REST API and the rights on a business object to call the vulnerable REST calls. The problem is fixed in version 15.5.12 and 16.0.5. There is a workaround available. The vulnerability requires the REST module to be enabled. Disabling the REST module or limiting the REST module via some firewall or web-server access rules to be accessed only be trusted systems will mitigate the risk.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4092 β€Ό

yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4097 β€Ό

phpservermon is vulnerable to Improper Neutralization of CRLF Sequences

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Hackers publish Vestas data following cyber attack πŸ“’

The move suggests the company didn’t comply with the hackers' ransom demands

πŸ“– Read

via "ITPro".
πŸ“’ IT Pro News in Review: Google sues Russian hackers, Microsoft hikes 365 prices, Spar hit by cyber attack πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ“’ South Australia government data breached in ransomware attack πŸ“’

Between 38,000 to 80,000 government employees might have been affected and potentially have had their data posted on the dark web

πŸ“– Read

via "ITPro".
πŸ“’ DarkMatter and former NSA officers sued over alleged phone hack of Saudi human rights activist πŸ“’

Loujain al-Hathloul alleges three ex-NSA mercenaries hacked her phone in 2017 and passed sensitive information on to Saudi Arabia

πŸ“– Read

via "ITPro".
πŸ“’ Avast to acquire self-sovereign identity firm Evernym πŸ“’

The acquisition will help Avast enhance its decentralized identity solutions

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft Outlook displays full contact details for spoofed senders πŸ“’

Product harvests details from Active Directory without checking, say researchers

πŸ“– Read

via "ITPro".
πŸ“’ LastPass announces integration with Google Workspace πŸ“’

Employers can now automatically provide employees with a LastPass account through Google’s directory integration

πŸ“– Read

via "ITPro".
πŸ“’ Russia blocks access to Tor in censorship push πŸ“’

The Russian government has blocked access to the project's website, and default Tor bridges are no longer working

πŸ“– Read

via "ITPro".
πŸ“’ Top 200 most common passwords of 2021 revealed πŸ“’

Unsurprisingly, the vast majority take less than a second to crack

πŸ“– Read

via "ITPro".
πŸ“’ UK and US agree deeper data-sharing partnership πŸ“’

The partnership will see the two nations form a comprehensive strategy to share data that aligns with both domestic data sharing and protection frameworks

πŸ“– Read

via "ITPro".
πŸ“’ HornetSecurity 365 Total Protection review: Keeping email squeaky clean πŸ“’

Tough email protection for Microsoft 365 that’s simple to deploy, easy to manage and very affordable

πŸ“– Read

via "ITPro".
πŸ“’ Android bug prevents users from calling emergency services πŸ“’

Google has confirmed that the glitch is affecting devices that have Microsoft Teams installed

πŸ“– Read

via "ITPro".
β€Ό CVE-2021-44833 β€Ό

The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
⚠ Log4Shell explained – how it works, why you need to know, and how to fix it ⚠

Find out how to deal with the Log2Shell vulnerability right across your estate. Yes, you need to patch, but that helps everyone else along with you!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-40858 β€Ό

Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44847 β€Ό

A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44154 β€Ό

An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_opt, which will then be triggered when running the diagnostics (via /goform/diagnostics_doit), resulting in a buffer overflow.

πŸ“– Read

via "National Vulnerability Database".