πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Security vulnerabilities in Umbraco CMS could lead to account takeover πŸ—“οΈ

Partial fix applied for two separate bugs in the open source software

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Preparing For the Next Cybersecurity Epidemic: Deepfakes πŸ•΄

Using blockchain, multifactor authentication, or signatures can help boost authentication security and reduce fraud.

πŸ“– Read

via "Dark Reading".
🦿 Phishing attack spoofs US Department of Labor to steal account credentials 🦿

A phishing campaign seen by email security provider Inky tries to trick its victims by inviting them to submit bids for alleged government projects.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-46104 β€Ό

An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38787 β€Ό

There is an integer overflow in the ION driver "/dev/ion" of Allwinner R818 SoC Android Q SDK V1.0 that could use the ioctl cmd "COMPAT_ION_IOC_SUNXI_FLUSH_RANGE" to cause a system crash (denial of service).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45808 β€Ό

jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44837 β€Ό

An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an admin user regarding the risk creation information in the /risque/administration/referentiel/json/create/categorie endpoint, using the id_cat1 query parameter to indicate the risk.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ GitHub Actions flaw that allowed code to be approved without review is addressed πŸ—“οΈ

Uncheck risky setting option offered

πŸ“– Read

via "The Daily Swig".
⚠ Serious Security: Apple Safari leaks private data via database API – what you need to know ⚠

There's a tiny data leakage bug in the WebKit browser engine... but it could act as a "supercookie" identifier for your browsing

πŸ“– Read

via "Naked Security".
πŸ•΄ (ISC)Β² Launches Entry-Level Cybersecurity Course πŸ•΄

Prospective entrants to the sector will receive instruction on fundamental cybersecurity concepts on which they will be evaluated during the new (ISC)Β² entry-level cybersecurity certification pilot exam.

πŸ“– Read

via "Dark Reading".
πŸ•΄ LogPoint Releases LogPoint 7, Adding SOAR Capabilities Within SIEM πŸ•΄

LogPoint 7 includes ready-made integrations to connect with existing security technologies, including endpoint protection, network detection, and threat management.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-46030 β€Ό

There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the database, and the next victim will be attacked when he accesses the tag module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38788 β€Ό

The Background service in Allwinner R818 SoC Android Q SDK V1.0 is used to manage background applications. Malicious apps can use the interface provided by the service to set the number of applications allowed to run in the background to 0 and add themselves to the whitelist, so that once other applications enter the background, they will be forcibly stopped by the system, causing a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ IRS Will Soon Require Selfies for Online Access β™ŸοΈ

If you created an online account to manage your tax records with the U.S. Internal Revenue Service (IRS), those login credentials will cease to work later this year. The agency says that by the summer of 2022, the only way to log in to irs.gov will be through ID.me, an online identity verification service that requires applicants to submit copies of bills and identity documents, as well as a live video feed of their faces via a mobile device.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Cloud Adoption Widens the Cybersecurity Skills Gap πŸ•΄

No matter what cloud services you employ, you are still responsible for protecting the security of your data.

πŸ“– Read

via "Dark Reading".
❌ Box 2FA Bypass Opens User Accounts to Attack ❌

A security bug in the file-sharing cloud app could have allowed attackers using stolen credentials to skate by one-time SMS code verification requirements.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-44299 β€Ό

A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33912 β€Ό

libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22310 β€Ό

IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23221 β€Ό

H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33913 β€Ό

libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of SPF_record_expand_data in spf_expand.c. The amount of overflowed data depends on the relationship between the length of an entire domain name and the length of its leftmost label. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.

πŸ“– Read

via "National Vulnerability Database".