πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41610 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-27339. Reason: This candidate is a reservation duplicate of CVE-2020-27339. Notes: All CVE users should reference CVE-2020-27339 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ McMenamins Breach Affected 23 Years of Employee Data πŸ•΄

The Oregon-based hospitality and dining business reports the data was compromised in a Dec. 12 ransomware attack.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Attackers Exploit Log4j Flaws in Hands-on-Keyboard Attacks to Drop Reverse Shells πŸ•΄

Microsoft says vulnerabilities present a "real and present" danger, citing high volume of scanning and attack activity targeting the widely used Apache logging framework.

πŸ“– Read

via "Dark Reading".
🦿 Google makes the perfect case for why you shouldn't use Chrome 🦿

Google says Manifest V3 is focused on security, privacy and performance, but it could also break Chrome browser extensions used by millions of people.

πŸ“– Read

via "Tech Republic".
❌ Microsoft Sees Rampant Log4j Exploit Attempts, Testing ❌

Microsoft says it's only going to get worse: It's seen state-sponsored and cyber-criminal attackers probing systems for the Log4Shell flaw through the end of December.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-21649 β€Ό

Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an <a> tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does not exist. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41388 β€Ό

Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process does not perform validation on new connections before accepting the connection. Thus any low privileged user can connect and call external methods defined in XPC service as root, elevating their privilege to the highest level.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21650 β€Ό

Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window, but you can upload a file with an .html extension. By uploading an SVG file with an html extension the upload filter can be bypassed. This causes Stored XSS. Also, after uploading a file the XSS attack is triggered upon a user viewing the file. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22045 β€Ό

VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with other issues to execute code on the hypervisor from a virtual machine.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ CrowdStrike Incorporates Intel CPU Telemetry into Falcon Sensor πŸ•΄

The Falcon sensor uses Intel PT telemetry to identify suspicious operations associated with hard-to-detect exploit techniques.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-43946 β€Ό

Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.21.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22567 β€Ό

Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41043 β€Ό

Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31589 β€Ό

BeyondTrust Secure Remote Access Base Software through 6.0.1 allows an attacker to achieve full admin access to the appliance, by tricking the administrator into creating a new admin account through an XSS/CSRF attack involving a crafted request to the /appliance/users?action=edit endpoint. This cross-site-scripting (XSS) vulnerability occurs when it does not properly sanitize an unauthenticated crafted web request to the server

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-15933 β€Ό

A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially sensitive software-version information via client-side resources inspection.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Indian academic bookseller Oswaal Books fixes alleged RCE and other serious vulnerabilities with Shopify relaunch πŸ—“οΈ

Researcher claims he found RCE, authentication bypass, CSRF flaws

πŸ“– Read

via "The Daily Swig".
❌ β€˜Malsmoke’ Exploits Microsoft’s E-Signature Verification ❌

The info-stealing campaign using ZLoader malware – previously used to deliver Ryuk and Conti ransomware – already has claimed more than 2,000 victims across 111 countries.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Web skimming attacks on hundreds of real estate websites deployed via cloud video hosting service πŸ—“οΈ

Attackers leverage software supply chain to compromise high-traffic sites

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Putting Ransomware Gangs Out of Business With AI πŸ•΄

Organizations need to take matters into their own hands with a new approach.

πŸ“– Read

via "Dark Reading".
⚠ Apple Home software bug could lock you out of your iPhone ⚠

The finder of this bug insists it "poses a serious risk". We're not so sure, but we recommend you take steps to avoid it anyway.

πŸ“– Read

via "Naked Security".
⚠ FTC threatens β€œlegal action” over unpatched Log4j and other vulns ⚠

Remember the Equifax breach? Remember the $700m penalty? In case you'd forgotten, here's the FTC to refresh your memory!

πŸ“– Read

via "Naked Security".