πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-24849 β€Ό

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How is Zero Trust Evolving to be More Continuous in Verifying Trust? πŸ•΄

For zero trust to be successful, organizations need to be able to check user identity, device posture, and overall behavior without adding friction to the experience.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-45255 β€Ό

The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45253 β€Ό

The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45252 β€Ό

Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Ubisoft confirms Just Dance video game data breach πŸ—“οΈ

Developer said no accounts had been improperly accessed

πŸ“– Read

via "The Daily Swig".
🦿 F-Secure uses flaw in at-home COVID-19 test to fake results 🦿

Security researchers used a Bluetooth vulnerability to change negative results to positive.

πŸ“– Read

via "Tech Republic".
❌ FBI: Another Zoho ManageEngine Zero-Day Under Active Attack ❌

APT attackers are using a security vulnerability in ManageEngine Desktop Central to take over servers, deliver malware and establish network persistence.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-4139 β€Ό

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Future of Ransomware πŸ•΄

Focusing on basic security controls and executing them well is the best way to harden your systems against an attack.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Browser security: Google fixes Chrome Site Isolation bypass bug πŸ—“οΈ

Vulnerability in Chrome’s service worker feature created chink in browser’s armor

πŸ“– Read

via "The Daily Swig".
πŸ•΄ A Year in Microsoft Bugs: The Most Critical, Overlooked & Hard to Patch πŸ•΄

Severe flaws in Microsoft Exchange and Windows Print Spooler stood out amid a wide range of vulnerabilities security teams were forced to prioritize in 2021.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Survey scams rekindled using advertising industry tricks to deliver tailor-made assaults πŸ—“οΈ

More bad men than Mad Men

πŸ“– Read

via "The Daily Swig".
❌ Two Active Directory Bugs Lead to Easy Windows Domain Takeover ❌

Microsoft is urging customers to patch two Active Directory domain controller bugs after a PoC tool was publicly released on Dec. 12.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2012-20001 β€Ό

PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45090 β€Ό

Stormshield Endpoint Security before 2.1.2 allows remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45089 β€Ό

Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45091 β€Ό

Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.

πŸ“– Read

via "National Vulnerability Database".
⚠ Apache’s other product: Critical bugs in β€˜httpd’ web server, patch now! ⚠

The Apache web server just got an update - this one is nothing to do with Log4j!

πŸ“– Read

via "Naked Security".
⚠ Log4Shell: The Movie… a short, safe visual tour for work and home ⚠

Be happy that your sysadmins are taking one (three, actually!) for the team right now... here's why!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-43587 β€Ό

Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges.

πŸ“– Read

via "National Vulnerability Database".