πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-44648 β€Ό

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44649 β€Ό

Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44650 β€Ό

Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.

πŸ“– Read

via "National Vulnerability Database".
⚠ Home routers with NetUSB support could have critical kernel hole ⚠

Got a router that supports USB access across the network? You might need a kernel update...

πŸ“– Read

via "Naked Security".
⚠ JavaScript developer destroys own projects in supply chain β€œlesson” ⚠

Two popular open source JavaScript packages recently got "hacked" in a symbolic gesture by the original project creator.

πŸ“– Read

via "Naked Security".
πŸ•΄ Patch Management Today: A Risk-Based Strategy to Defeat Cybercriminals πŸ•΄

By combining risk-based vulnerability prioritization and automated patch intelligence, organizations can apply patches based on threat level. Part 2 of 3.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Patch Tuesday: Web security issues in the spotlight in Microsoft’s bumper January update πŸ—“οΈ

β€˜Wormable’ flaw in HTTP Protocol Stack causes concern

πŸ“– Read

via "The Daily Swig".
πŸ›  Proxmark3 4.14831 πŸ› 

This is a custom firmware written for the Proxmark3 device. It extends the currently available firmware. This release is nicknamed Frostbit.

πŸ“– Read

via "Packet Storm Security".
πŸ—“οΈ Cybersecurity conferences 2022: A rundown of online, in person, and β€˜hybrid’ events πŸ—“οΈ

With many events choosing to retain virtual elements forced on them by the pandemic, there’s now an abundance of online content to choose from

πŸ“– Read

via "The Daily Swig".
⚠ Wormable Windows HTTP hole – what you need to know ⚠

One bug in the January 2022 Patch Tuesday list is getting lots of attention: "HTTP Protocol Stack Remote Code Execution Vulnerability".

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-44651 β€Ό

Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44652 β€Ό

Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.

πŸ“– Read

via "National Vulnerability Database".
🦿 US government urges organizations to prepare for Russian-sponsored cyber threats 🦿

Though the feds don't cite any specific threat, a joint advisory from CISA, the FBI and the NSA offers advice on how to detect and mitigate cyberattacks sponsored by Russia.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Critical Infrastructure Security and a Case for Optimism in 2022 πŸ•΄

The new US infrastructure law will fund new action to improve cybersecurity across rail, public transportation, the electric grid, and manufacturing.

πŸ“– Read

via "Dark Reading".
❌ New York AG Warns 17 Firms of Credential Attacks ❌

Sponsored: Password security is highlighted in attorney general warning to New York state businesses.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-0015 β€Ό

A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45388 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-45608. Reason: This candidate is a reservation duplicate of CVE-2021-45608. Notes: All CVE users should reference CVE-2021-45608 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43436 β€Ό

MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45411 β€Ό

In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45445 β€Ό

Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28377 β€Ό

ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".