πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-20876 β€Ό

Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an administrative privilege to obtain sensitive information stored in the hierarchy above the directory on the published site's server via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20827 β€Ό

Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the attacker may access the PLC Web server and hijack the PLC, and manipulation of the PLC output and/or suspension of the PLC may be conducted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20874 β€Ό

Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20875 β€Ό

Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks by having a user to access a specially crafted URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20826 β€Ό

Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from the communication between the PLC and the software. As a result, the complete access privileges to the PLC Web server may be obtained, and manipulation of the PLC output and/or suspension of the PLC may be conducted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23772 β€Ό

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4072 β€Ό

elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
⚠ The cool retro phone with a REAL DIAL… plus plenty of IoT problems ⚠

You know you want one, because this retro phone is NOT A TOY... except when it comes to cybersecurity.

πŸ“– Read

via "Naked Security".
🦿 Switch to a well-paid tech career in 2022: Check out these 200+ IT courses 🦿

Training for a lucrative tech career is easier and less expensive than you might think. Check out these online courses on programming, cybersecurity, project management and more.

πŸ“– Read

via "Tech Republic".
⚠ SFW! The Top N Cyber­security Stories of 2021 (for small positive integer values of N) ⚠

Happy Holidays! Our Top N stories, all totally SFW!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-37567 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32468 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37560 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32469 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37565 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37562 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37583 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37584 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37571 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37570 β€Ό

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols.

πŸ“– Read

via "National Vulnerability Database".