November 4, 2021 at 11:00PM

■■□□□ Remote code execution, SQL injection bugs uncovered in Pentaho Business Analytics software. https://portswigger.net/daily-swig/remote-code-execution-sql-injection-bugs-uncovered-in-pentaho-business-analytics-software https://t.me/cKure/9957

November 4, 2021 at 10:24PM

■□□□□ Attackers are actively exploiting an “old” vulnerability (CVE-2021-22205) to take over on-premise GitLab servers, Rapid7 researcher Jacob Baines warns. The additional bad news is that at least half of the 60,000 internet-facing GitLab installations the company detects are not patched against this issue.  https://t.me/cKure/9953

November 4, 2021 at 09:24PM

■■■■■ uXSS in Google Chrome. https://portswigger-net.cdn.ampproject.org/c/s/portswigger.net/daily-swig/amp/dangerous-uxss-bug-in-google-chromes-new-tab-page-bypassed-security-features https://t.me/cKure/9951

November 4, 2021 at 06:32PM

■■□□□ Privacy | China GFWatchA: Longitudinal Measurement Platform Built to Monitor China’s DNS Censorship at Scale. https://citizenlab.ca/2021/11/gfwatch-a-longitudinal-measurement-platform-built-to-monitor-chinas-dns-censorship-at-scale/ https://t.me/cKure/9950