πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-22989 β€Ό

My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service. Addressed the vulnerability by adding defenses against stack overflow issues.c

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34933 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14911.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34997 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AppStudioUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13894.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0178 β€Ό

snipe-it is vulnerable to Improper Access Control

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45760 β€Ό

GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_list_last(). This vulnerability allows attackers to cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23218 β€Ό

The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42551 β€Ό

Cross-site Scripting (XSS) vulnerability in the search functionality of AlCoda NetBiblio WebOPAC allows an unauthenticated user to craft a reflected Cross-Site Scripting attack. This issue affects: AlCoda NetBiblio WebOPAC versions prior to 4.0.0.320; versions later than 4.0.0.328. This issue does not affect: AlCoda NetBiblio WebOPAC version 4.0.0.335 and later versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23222 β€Ό

kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23219 β€Ό

The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20698 β€Ό

A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an invalid pointer read. An attacker could exploit this vulnerability by sending a crafted OOXML file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33962 β€Ό

China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript] ⚠

Latest episode -listen to it or read it now!

πŸ“– Read

via "Naked Security".
❌ Three Plugins with Same Bug Put 84K WordPress Sites at Risk ❌

Researchers discovered vulnerabilities that can allow for full site takeover in login and e-commerce add-ons for the popular website-building platform.

πŸ“– Read

via "Threat Post".
⚠ REvil ransomware crew allegedly busted in Russia, says FSB ⚠

The Russian Federal Security Bureau has just published a report about the investigation and arrest of the infamous "REvil" ransomware crew.

πŸ“– Read

via "Naked Security".
❌ Russian Security Takes Down REvil Ransomware Gang ❌

The country's FSB said that it raided gang hideouts; seized currency, cars and personnel; and neutralized REvil's infrastructure.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Apache Software Foundation warns its patching efforts are being undercut by use of end-of-life software πŸ—“οΈ

Non-profit shares metrics in its latest annual security review of 350-plus projects

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0213 β€Ό

vim is vulnerable to Heap-based Buffer Overflow

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ What's Next for Patch Management: Automation πŸ•΄

The next five years will bring the widespread use of hyperautomation in patch management. Part 3 of 3.

πŸ“– Read

via "Dark Reading".
❌ β€˜Be Afraid:’ Massive Cyberattack Downs Ukrainian Gov’t Sites ❌

As Moscow moves troops and threatens military action, about 70 Ukrainian government sites were hit. β€œBe afraid” was scrawled on the Foreign Ministry site.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Researcher discloses alleged zero-day vulnerabilities in NUUO NVRmini2 recording device πŸ—“οΈ

Exploit code has also been released for flaws that supposedly date back to 2016

πŸ“– Read

via "The Daily Swig".
❌ Real Big Phish: Mobile Phishing & Managing User Fallibility ❌

Phishing is more successful than ever. Daniel Spicer, CSO of Ivanti, discusses emerging trends in phishing, and using zero-trust security to patch the human vulnerabilities underpinning the spike.

πŸ“– Read

via "Threat Post".