๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2021-22567 โ€ผ

Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-41043 โ€ผ

Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-31589 โ€ผ

BeyondTrust Secure Remote Access Base Software through 6.0.1 allows an attacker to achieve full admin access to the appliance, by tricking the administrator into creating a new admin account through an XSS/CSRF attack involving a crafted request to the /appliance/users?action=edit endpoint. This cross-site-scripting (XSS) vulnerability occurs when it does not properly sanitize an unauthenticated crafted web request to the server

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-15933 โ€ผ

A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially sensitive software-version information via client-side resources inspection.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ—“๏ธ Indian academic bookseller Oswaal Books fixes alleged RCE and other serious vulnerabilities with Shopify relaunch ๐Ÿ—“๏ธ

Researcher claims he found RCE, authentication bypass, CSRF flaws

๐Ÿ“– Read

via "The Daily Swig".
โŒ โ€˜Malsmokeโ€™ Exploits Microsoftโ€™s E-Signature Verification โŒ

The info-stealing campaign using ZLoader malware โ€“ previously used to deliver Ryuk and Conti ransomware โ€“ already has claimed more than 2,000 victims across 111 countries.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ—“๏ธ Web skimming attacks on hundreds of real estate websites deployed via cloud video hosting service ๐Ÿ—“๏ธ

Attackers leverage software supply chain to compromise high-traffic sites

๐Ÿ“– Read

via "The Daily Swig".
๐Ÿ•ด Putting Ransomware Gangs Out of Business With AI ๐Ÿ•ด

Organizations need to take matters into their own hands with a new approach.

๐Ÿ“– Read

via "Dark Reading".
โš  Apple Home software bug could lock you out of your iPhone โš 

The finder of this bug insists it "poses a serious risk". We're not so sure, but we recommend you take steps to avoid it anyway.

๐Ÿ“– Read

via "Naked Security".
โš  FTC threatens โ€œlegal actionโ€ over unpatched Log4j and other vulns โš 

Remember the Equifax breach? Remember the $700m penalty? In case you'd forgotten, here's the FTC to refresh your memory!

๐Ÿ“– Read

via "Naked Security".
๐Ÿ—“๏ธ Prosecutors file additional charges against former Uber security chief over 2016 data breach โ€˜cover upโ€™ ๐Ÿ—“๏ธ

Alleged misuse of bug bounty and failure to disclose breach leads to criminal charges

๐Ÿ“– Read

via "The Daily Swig".
โ€ผ CVE-2022-22110 โ€ผ

In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force usersรขโ‚ฌโ„ข passwords with minimal to no computational effort.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-22108 โ€ผ

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-22111 โ€ผ

In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administratorรขโ‚ฌโ„ขs. This allows the attacker to gain access to the highest privileged user in the application.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-22109 โ€ผ

In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store malicious scripts in the title field of new tasks. These scripts are executed in a victimรขโ‚ฌโ„ขs browser when they open the รขโ‚ฌล“/tasksรขโ‚ฌ๏ฟฝ page to view all the tasks.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-22107 โ€ผ

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not authorized to view the calendar at all.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Why We Need To Reframe the False-Positive Problem ๐Ÿ•ด

Efforts to tune or build behavior- or signature-based threat identification requires time and effort most organizations don't have.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿฆฟ Behind the scenes: A day in the life of a cybersecurity curriculum director ๐Ÿฆฟ

The Kennedy Space Center kick-started Andee Harston's career in cybersecurity. Here's how she worked her way up to overseeing the cybersecurity curriculum for Infosec.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿฆฟ MalSmoke attack: Zloader malware exploits Microsoft's signature verification to steal sensitive data ๐Ÿฆฟ

Already impacting more than 2,000 victims, the malware is able to modify a DLL file digitally signed by Microsoft, says Check Point Research.

๐Ÿ“– Read

via "Tech Republic".
โŒ FTC to Go After Companies that Ignore Log4j โŒ

Companies that fail to protect secure consumer data from Log4J attacks are at risk of facing Equifax-esque legal action and fines, the FTC warned.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ•ด Which Cloud Strategy Is Right For My Organization's Security Needs? ๐Ÿ•ด

The massive Amazon Web Services outage in December had many security leaders asking whether they should be going multicloud or multiregion for their cloud environments.

๐Ÿ“– Read

via "Dark Reading".