πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-23220 β€Ό

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Crime Shop Sells Hacked Logins to Other Crime Shops β™ŸοΈ

Up for the "Most Meta Cybercrime Offering" award this year is Accountz Club, a new cybercrime store that sells access to purloined accounts at services built for cybercriminals, including shops peddling stolen payment cards and identities, spamming tools, email and phone bombing services, and those selling authentication cookies for a slew of popular websites.

πŸ“– Read

via "Krebs on Security".
❌ McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges ❌

McAfee has patched two high-severity bugs in its Agent component, one of which can allow attackers to achieve arbitrary code execution with SYSTEM privileges.

πŸ“– Read

via "Threat Post".
❌ 20K WordPress Sites Exposed by Insecure Plugin REST-API ❌

The WordPress WP HTML Mail plugin for personalized emails is vulnerable to code injection and phishing due to XSS.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-4879 β€Ό

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4877 β€Ό

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46309 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4875 β€Ό

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190838.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46308 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4016 β€Ό

Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset_info.json or file_info.json, leading to a loss of confidentiality. This issue was fixed in Rapid7 Insight Agent 3.1.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4876 β€Ό

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190839.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0323 β€Ό

Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 1/21 πŸ”

News on the Ukrainian wiper attack, MIcrosoft disables macros in Excel by default, and more - catch up on the infosec news of the week with the Friday Five!

πŸ“– Read

via "".
❌ Merck Awarded $1.4B Insurance Payout over NotPetya Attack ❌

Court rules β€˜War or Hostile Acts’ exclusion doesn’t apply to the pharma giant's 2017 cyberattack.

πŸ“– Read

via "Threat Post".
πŸ•΄ REvil Ransomware Gang Arrests Trigger Uncertainty, Concern in Cybercrime Forums πŸ•΄

Threat actors from Eastern Europe seen expressing some concern about Russia being a safe place for them to continue operating, researchers say.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-40595 β€Ό

SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33966 β€Ό

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31562 β€Ό

The SSL/TLS configuration of Fresenius Kabi Agilia Link + version 3.0 has serious deficiencies that may allow an attacker to compromise SSL/TLS sessions in different ways. An attacker may be able to eavesdrop on transferred data, manipulate data allegedly secured by SSL/TLS, and impersonate an entity to gain access to sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40247 β€Ό

SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44464 β€Ό

Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may gain privileges on all installations of this software.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23128 β€Ό

Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), ICONICS GENESIS64 versions 10.95.3 to 10.97, ICONICS Hyper Historian versions 10.95.3 to 10.97, ICONICS AnalytiX versions 10.95.3 to 10.97 and ICONICS MobileHMI versions 10.95.3 to 10.97 allows a remote unauthenticated attacker to bypass the authentication of MC Works64, GENESIS64, Hyper Historian, AnalytiX and MobileHMI, and gain unauthorized access to the products, by sending specially crafted WebSocket packets to FrameWorX server, one of the functions of the products.

πŸ“– Read

via "National Vulnerability Database".