πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2018-11800

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Adobe Updates Fix Critical Vulnerabilities in ColdFusion, Campaign, and Flash Player πŸ”

Adobe is urging users to patch 10 vulnerabilities, five of them critical, in three different products this week.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ 'Have I Been Pwned' Is Up for Sale πŸ•΄

Troy Hunt, who has been running HIBP solo for six years, launched "Project Svalbard" so the site can evolve with more resources, funding, and support.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft Patches Four Publicly-Known Vulnerabilities ❌

In total, 88 unique vulnerabilities were patched as part of Microsoft’s June Patch Tuesday security bulletin.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft Issues Fixes for 88 Vulnerabilities πŸ•΄

Four of the flaws are publicly known but none have been listed as under active attack.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-18378

In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18377

An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10760

On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7471

An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5330

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5157

On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5156

An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Command Injection via the cgi-bin/script query string.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cross-Site Scripting Errors Continue to Be Most Common Web App Flaw πŸ•΄

In vulnerability disclosure programs, organizations are paying more in total for XSS issues than any other vulnerability type, HackerOne says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Suppliers Spotlighted After Breach of Border Agency Subcontractor πŸ•΄

Attackers increasingly use third-party service providers to bypass organizations' security. The theft of images from US Customs and Border Protection underscores the weakness suppliers can create.

πŸ“– Read

via "Dark Reading: ".
⚠ Hackers stole photos of travelers and license plates from subcontractor ⚠

Critics say if the US can't protect such data - which was improperly stored by a subcontractor - it shouldn't collect it.

πŸ“– Read

via "Naked Security".
⚠ Radiohead releases β€˜OK Computer’ sessions that hacker tried to ransom ⚠

The band shrugged off the threat and released the files on Bandcamp. They're long and not very interesting, they said.

πŸ“– Read

via "Naked Security".
⚠ FBI warns users to be wary of phishing sites abusing HTTPS ⚠

Why you shouldn't trust a website simply because it's secured using HTTPS and backed by the green padlock symbol.

πŸ“– Read

via "Naked Security".
❌ Full Insight into the Internal Environment with Cynet Free Visibility ❌

The Cynet 360 platform Free Visibility Offering is focused on IT and security professionals who know a lack of visibility is a main challenge in their daily responsibilities as end-users and service providers. 

πŸ“– Read

via "Threatpost".
❌ Full Insight into the Internal Environment with Cynet Free Visibility ❌

The Cynet 360 platform Free Visibility Offering is focused on IT and security professionals who know a lack of visibility is a main challenge in their daily responsibilities as end-users and service providers. 

πŸ“– Read

via "Threatpost".
❌ New FormBook Dropper Harbors Obfuscation, Persistence ❌

Never-before-seen dropper found in FormBook samples that has increased persistence and obfuscation capabilities.

πŸ“– Read

via "Threatpost".
πŸ” 84% of US employees have never heard of GDPR πŸ”

A survey of corporate employees by insider threat management company ObserveIT reveals a greater understanding of privacy laws in the UK than in the US.

πŸ“– Read

via "Security on TechRepublic".