πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-36750 β€Ό

ENC DataVault 7.1.1W and VaultAPI v67, which is currently being used in various other applications, mishandles key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40612 β€Ό

An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Anti-cheating browser extension fails web security examination πŸ—“οΈ

XSS flaw in Proctorio gets resolved

πŸ“– Read

via "The Daily Swig".
🦿 Conti ransomware is exploiting the Log4Shell vulnerability to the tune of millions 🦿

Log4Shell is a dangerous security concern β€” and now Conti, a prominent ransomware group, is exploiting it to attack vulnerable servers to extort millions of dollars.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Bug bounty platforms handling thousands of Log4j vulnerability reports πŸ—“οΈ

Leading platforms report back from the front line as vendors grapple with landmark bug Bug bounty hunters have already submitted thousands of vulnerability reports related to the Apache Log4j bug that

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-45418 β€Ό

Certain Starcharge products are vulnerable to Directory Traversal via main.cgi. The affected products include: Nova 360 Cabinet <=1.3.0.0.6 - Fixed: 1.3.0.0.9 and Titan 180 Premium <=1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0.

πŸ“– Read

via "National Vulnerability Database".
⚠ Apache’s other product: Critical bugs in β€˜httpd’ web server, patch now! ⚠

The Apache web server just got an update - this one is nothing to do with Log4j!

πŸ“– Read

via "Naked Security".
⚠ Plundered bitcoins recovered by FBI – all 3,879-and-one-sixth of them! ⚠

Phew! An audacious crime... that didn't work out.

πŸ“– Read

via "Naked Security".
❌ Critical Apache HTTPD Server Bugs Could Lead to RCE, DoS ❌

Don't freak: It's got nothing to do with Log4Shell, except it may be just as far-reaching as Log4j, given HTTPD's tendency to tiptoe into software projects.

πŸ“– Read

via "Threat Post".
❌ PYSA Emerges as Top Ransomware Actor in November ❌

Overtaking the Conti ransomware gang, PYSA finds success with government-sector attacks.

πŸ“– Read

via "Threat Post".
❌ All in One SEO Plugin Bug Threatens 3M Websites with Takeovers ❌

A critical privilege-escalation vulnerability could lead to backdoors for admin access nesting in web servers.

πŸ“– Read

via "Threat Post".
❌ Time to Ditch Big-Brother Accounts for Network Scanning ❌

Yaron Kassner, CTO and co-founder of Silverfort, discusses why using all-seeing privileged accounts for monitoring is bad practice.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-39013 β€Ό

IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID: 213651.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45260 β€Ό

A null pointer dereference vulnerability exists in gpac 1.1.0 in the lsr_read_id.part function, which causes a segmentation fault and application crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44659 β€Ό

Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4113 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45419 β€Ό

Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <= 1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0 and Titan 180 Premium <= 1.3.0.0.6 - Fixed: 1.3.0.0.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44733 β€Ό

A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45258 β€Ό

A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation fault and application crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43630 β€Ό

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43156 β€Ό

In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.

πŸ“– Read

via "National Vulnerability Database".