πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-36722 β€Ό

Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4175 β€Ό

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45885 β€Ό

An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25993 β€Ό

In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attackerÒ€ℒs server and will lead to account takeover when accessed by the victim.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23727 β€Ό

This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4187 β€Ό

vim is vulnerable to Use After Free

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36724 β€Ό

ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43876 β€Ό

Microsoft SharePoint Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4188 β€Ό

mruby is vulnerable to NULL Pointer Dereference

πŸ“– Read

via "National Vulnerability Database".
🦿 Learn highly marketable ethical hacking skills for less than $45 🦿

Even if you have no tech experience, you can develop valuable skills with the online training offered by The Super-Sized Ethical Hacking Bundle.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-45427 β€Ό

Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ In the Fight Against Cybercrime, Takedowns Are Only Temporary πŸ•΄

Disrupting access to servers and infrastructure continues to interfere with cybercrime activity, but it's far from a perfect strategy.

πŸ“– Read

via "Dark Reading".
⚠ Instagram copyright infringment scams – don’t get sucked in! ⚠

We deconstructed a copyright phish so you don't have to. Be warned: the crooks are getting better at these scams...

πŸ“– Read

via "Naked Security".
πŸ•΄ Zero Trust and Access: Protecting the Keys to the Kingdom πŸ•΄

Zero trust moves the control pane closer to the defended asset and attempts to tightly direct access and privileges.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-45818 β€Ό

SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to can lead to HTTP response splitting.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43861 β€Ό

Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch. There are no known workarounds aside from upgrading.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45815 β€Ό

Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Swig Security Review 2021 – Part II πŸ—“οΈ

Key thinkers on the biggest security stories and trends in 2021

πŸ“– Read

via "The Daily Swig".
❌ APT β€˜Aquatic Panda’ Targets Universities with Log4Shell Exploit Tools ❌

Researchers from CrowdStrike disrupted an attempt by the threat group to steal industrial intelligence and military secrets from an academic institution.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ HCL DX vendor β€˜could not reproduce’ allegedly critical vulnerabilities πŸ—“οΈ

Disclosure process for bugs in HCL DX – formerly WebSphere Portal – seemingly went awry

πŸ“– Read

via "The Daily Swig".