πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Was COMELEC hacked? Philippines Commission on Elections casts doubt on data breach claims πŸ—“οΈ

Local newspaper alleges that usernames and PINs of vote-counting machines were stolen

πŸ“– Read

via "The Daily Swig".
⚠ S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis [Podcast + Transcript] ⚠

Latest epsiode - listen now!

πŸ“– Read

via "Naked Security".
πŸ—“οΈ European Commission launches new open source software bug bounty program πŸ—“οΈ

Hackers are invited to test services used by EU agencies

πŸ“– Read

via "The Daily Swig".
⚠ Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft ⚠

The company has put out a brief security report that summarises the 'what', but not yet the 'how' or 'why'.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-46201 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40855 β€Ό

The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46200 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46307 β€Ό

An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35003 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14655.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35004 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link TL-WA1201 1.0.1 Build 20200709 rel.66244(5553) wireless access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14656.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46198 β€Ό

An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19861 β€Ό

When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt_rdf) byte data can be copied, causing heap overflow information leakage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23220 β€Ό

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Crime Shop Sells Hacked Logins to Other Crime Shops β™ŸοΈ

Up for the "Most Meta Cybercrime Offering" award this year is Accountz Club, a new cybercrime store that sells access to purloined accounts at services built for cybercriminals, including shops peddling stolen payment cards and identities, spamming tools, email and phone bombing services, and those selling authentication cookies for a slew of popular websites.

πŸ“– Read

via "Krebs on Security".
❌ McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges ❌

McAfee has patched two high-severity bugs in its Agent component, one of which can allow attackers to achieve arbitrary code execution with SYSTEM privileges.

πŸ“– Read

via "Threat Post".
❌ 20K WordPress Sites Exposed by Insecure Plugin REST-API ❌

The WordPress WP HTML Mail plugin for personalized emails is vulnerable to code injection and phishing due to XSS.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-4879 β€Ό

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4877 β€Ό

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46309 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4875 β€Ό

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190838.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46308 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.

πŸ“– Read

via "National Vulnerability Database".