🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2021-25990

In “ifme�, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.

📖 Read

via "National Vulnerability Database".
CVE-2021-44161

Changing MOTP (Mobile One Time Password) systemâ€s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.

📖 Read

via "National Vulnerability Database".
CVE-2021-25989

In “ifme�, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.

📖 Read

via "National Vulnerability Database".
CVE-2021-44160

Carinal Tien Hospital Health Report Systemâ€s login page has improper authentication, a remote attacker can acquire another general userâ€s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.

📖 Read

via "National Vulnerability Database".
CVE-2021-25991

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to self-ban themself leading to their deactivation from Ifme account and complete loss of admin access in Ifme.

📖 Read

via "National Vulnerability Database".
CVE-2021-25988

In “ifme�, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.

📖 Read

via "National Vulnerability Database".
🗓️ Indian authorities set to tighten data breach laws in 2022 🗓️

Credit card storage rules and 72-hour breach notification deadline due to come into play next year

📖 Read

via "The Daily Swig".
Cryptomining Attack Exploits Docker API Misconfiguration Since 2019

Campaign exploits misconfigured Docker APIs to gain network entry and ultimately sets up a backdoor on compromised hosts to mine cryptocurrency.

📖 Read

via "Threat Post".
5 Cybersecurity Trends to Watch in 2022

Here’s what cybersecurity watchers want infosec pros to know heading into 2022.  

📖 Read

via "Threat Post".
🗓️ LastPass quells cyber-attack fears, blames email notification surge on ‘glitch’ 🗓️

Password vault investigation reveals no evidence of credential stuffing activity

📖 Read

via "The Daily Swig".
SFW! The Top N Cyber­security Stories of 2021 (for small positive integer values of N)

Happy Holidays! Our Top N stories, all totally SFW!

📖 Read

via "Naked Security".
CVE-2021-38680

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.20 and later

📖 Read

via "National Vulnerability Database".
CVE-2021-38687

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later

📖 Read

via "National Vulnerability Database".
CVE-2021-35035

A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.

📖 Read

via "National Vulnerability Database".
CVE-2021-35034

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

📖 Read

via "National Vulnerability Database".
CVE-2021-38688

An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and later

📖 Read

via "National Vulnerability Database".
🕴 Why Cyber Due Diligence Is Essential to the M&A Process 🕴

That announcement may feel good, but if your prospective acquisition's cybersecurity levels are substandard, it might be best to hold off.

📖 Read

via "Dark Reading".
Log4Shell vulnerability Number Four: “Much ado about something”

It's a Log4j bug, and you ought to patch it. But we don't think it's a critical crisis like the last one.

📖 Read

via "Naked Security".
🗓️ Swig Security Review 2021 – Part I 🗓️

Key thinkers on the biggest security stories and trends in 2021

📖 Read

via "The Daily Swig".
CVE-2021-36723

Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.

📖 Read

via "National Vulnerability Database".
CVE-2021-4176

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

📖 Read

via "National Vulnerability Database".