πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ What is a 502 bad gateway and how do you fix it? πŸ“’

We explain what this networking error means for users and website owners

πŸ“– Read

via "ITPro".
πŸ€”1
πŸ“’ NEC and Fortinet partner to deliver high-performance security for 5G networks πŸ“’

The carrier solution will ensure end-to-end security while CSPs contend with increased traffic

πŸ“– Read

via "ITPro".
πŸ“’ Block accused of woefully mishandling data breach affecting 8.2 million users πŸ“’

Class-action lawsuit claims the company took too long to inform customers and failed to provide a sufficient explanation for the breach

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ More than 130 organisations affected by β€œinexperienced” Twilio hackers πŸ“’

A thorough investigation revealed sophisticated methods coupled with relatively unsophisticated tooling

πŸ“– Read

via "ITPro".
πŸ•΄ LastPass Suffers Data Breach, Source Code Stolen πŸ•΄

Researchers warned that cyberattackers will be probing the code for weaknesses to exploit later.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-3688 β€Ό

A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3859 β€Ό

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20260 β€Ό

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4215 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25625 β€Ό

A malicious unauthorized PAM user can access the administration configuration data and change the values.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3427 β€Ό

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3754 β€Ό

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3651 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3574 β€Ό

A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4216 β€Ό

A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3669 β€Ό

A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35939 β€Ό

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3864 β€Ό

A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3644 β€Ό

A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3856 β€Ό

ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3691 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".