πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ More Than 70% of SOC Analysts Experiencing Burnout πŸ•΄

Nearly 65% of security operations center (SOC) analysts are likely to change jobs in the next year, survey shows.

πŸ“– Read

via "Dark Reading".
πŸ‘1
❌ Massive Meris Botnet Embeds Ransomware Notes from REvil ❌

Notes threatening to tank targeted companies' stock price were embedded into the DDoS ransomware attacks as a string_of_text directed to CEOs and webops_geeks in the URL.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-46353 β€Ό

An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacker to send a specially crafted HTTP request and gain knowledge of different absolute paths that are being used by the web application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46384 β€Ό

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¢¢ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44827 β€Ό

There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40846 β€Ό

An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27756 β€Ό

"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43590 β€Ό

Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32008 β€Ό

This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25312 β€Ό

An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access. This issue is fixed in Apache Any23 2.7.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ The new rules of ransomware πŸ“’

The rise in working from home has brought with it a rise in ransomware attacks, but an effective backup routine can guard against disaster

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft releases Defender for Azure Cosmos DB in preview πŸ“’

The database protection service is exclusive to Microsoft Defender for Cloud users

πŸ“– Read

via "ITPro".
πŸ“’ Anonymous hacks website of Russian Space Research Institute πŸ“’

Russia’s lunar missions files were obtained through a brute-force attack on a private service hosted by Roscosmos

πŸ“– Read

via "ITPro".
πŸ“’ Cisco patches critical bugs in collaboration products πŸ“’

Attackers could exploit the flaw to run their own code on Cisco's video conferencing servers

πŸ“– Read

via "ITPro".
πŸ“’ IT Pro News In Review: Compromised Nvidia data, protesters boycott Russian tech, Conti data breach πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ“’ OneWeb suspends satellite launch from Russian spaceport πŸ“’

The decision follows Roscosmos’ demand that the UK sell its 20% stake in OneWeb purchased in 2020

πŸ“– Read

via "ITPro".
πŸ‘1
β€Ό CVE-2022-25069 β€Ό

Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25465 β€Ό

Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25044 β€Ό

Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0849 β€Ό

Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

πŸ“– Read

via "National Vulnerability Database".
⚠ Firefox patches two in-the-wild exploits – update now! ⚠

Firefox just published a double-zero-day patch - "remote code execution" combined with "sandbox escape". Update now!

πŸ“– Read

via "Naked Security".