πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-0121 β€Ό

hoppscotch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22704 β€Ό

The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46141 β€Ό

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46143 β€Ό

In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0122 β€Ό

forge is vulnerable to URL Redirection to Untrusted Site

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46142 β€Ό

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Insecure Amazon S3 bucket exposed personal data on 500,000 Ghanaian graduates πŸ—“οΈ

Cloud storage misconfiguration left sensitive data openly accessible

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-22707 β€Ό

In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes), as demonstrated by remote denial of service (daemon crash).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36737 β€Ό

The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36738 β€Ό

The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46145 β€Ό

The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expiring rolling code and counter resynchronization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36739 β€Ό

The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Kazakhstan government shuts down internet following country-wide protests πŸ—“οΈ

This isn’t the first time the landlocked nation has restricted web access for citizens

πŸ“– Read

via "The Daily Swig".
⚠ FTC threatens β€œlegal action” over unpatched Log4j and other vulns ⚠

Remember the Equifax breach? Remember the $700m penalty? In case you'd forgotten, here's the FTC to refresh your memory!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-44564 β€Ό

A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and knowledge of its IP address. The attack exploits the unsecured communication channel used between the administration tool Easyconnect and the SYNC device (in the affected family of SYNC products).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44351 β€Ό

An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep64: Log4Shell again, scammers keeping busy, and Apple Home bug [Podcast + Transcript] ⚠

We're back for 2022 - listen now!

πŸ“– Read

via "Naked Security".
❌ Attackers Exploit Flaw in Google Docs’ Comments Feature ❌

A wave of phishing attacks identified in December targeting mainly Outlook users are difficult for both email scanners and victims to flag, researchers said.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ New York Attorney General flags 1.1 million online accounts compromised by credential stuffing attacks πŸ—“οΈ

Bureau of Internet and Technology helped affected organizations secure accounts and bolster defenses

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Hybrid Multicloud Strategies Are Keeping the Public Sector at the Forefront of Threat Mitigation πŸ•΄

Zero trust, DevSecOps, and agile methodologies are critical in bridging the power of commercial multicloud environments and the security of private data centers.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-44590 β€Ό

In libming 0.4.8, a memory exhaustion vulnerability exist in the function cws2fws in util/main.c. Remote attackers could launch denial of service attacks by submitting a crafted SWF file that exploits this vulnerability.

πŸ“– Read

via "National Vulnerability Database".