September 24, 2020 at 10:45AM

■■■■□ CVE-2020-8147: Flaw in input validation in npm package utils-extend version 1.0.8 and previous versions may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend. https://vulmon.com/vulnerabilitydetails?qid=CVE-2020-8147 https://t.me/cKure/5623

September 24, 2020 at 07:23AM

■■■■■ UAC bypass (Privilege escalation) https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_diskcleanup_hijack.toml https://mobile.twitter.com/SBousseaden/status/1308683468168146945 https://t.me/cKure/5620

September 23, 2020 at 02:28PM

■■■□□ #DataLeak: Shopify discloses security incident caused by two rogue employees. https://www.zdnet.com/article/shopify-discloses-security-incident-caused-by-two-rogue-employees/#ftag=R#DataLeak: Shopify discloses security incident caused by two rogue employees. https://www.zdnet.com/article/shopify-discloses-security-incident-caused-by-two-rogue-employees/#ftag=RSSbaffb68 https://t.me/cKure/5614