Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-28026PUBLISHED: 2021-03-05jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using djxl, an attacker can trigger arbitrary code execution or a denial of service.
CVE-2021-27907PUBLISHED: 2021-03-05
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the context of the user's browser. The javasc...
CVE-2021-20663PUBLISHED: 2021-03-05
Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and ea...
CVE-2021-20664PUBLISHED: 2021-03-05
Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and earlie...
CVE-2021-20665PUBLISHED: 2021-03-05
Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and ear...
User Rank: Apprentice
2/17/2019 | 1:26:23 AM
How did I engage? I tried to help a friend, inserted my usb stick, turned on the internet as it was needed for my action and Gradcrab 5.1 activated.
I didn't realize it until I noticed that some files from my usb stick changed names.
I was also amazed by the led of usb stick running wild after turning internet on. I knew something was wrong. That was the crypting doing its job.
In 3 minutes the entire folders with txt, docs and zip files were damaged / encrypted.
Luckly I had backups and so my friend, but one thing is obvious: Windows Defender defended NOTHING.
Other systems from same place with Bitdefender installed with Antiransomware and preboot options active were protected.
This is not advertising to this AV provider, it's just a happy case with one damaged computer from 7.
We saved some encrypted files for future use and see if any decryptor will help, but it will be at least 6 months until one will be public.
Thank you