πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-3816 β€Ό

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23843 β€Ό

The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to configuration data on the device. An attacker can exploit this vulnerability to manipulate the device\'s configuration or make it unresponsive in the local network. The attacker needs to have access to the local network, typically even the same subnet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23046 β€Ό

PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23045 β€Ό

PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21701 β€Ό

Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE` permission for `gateways.gateway.networking.k8s.io` objects can escalate this privilege to create other resources that they may not have access to, such as `Pod`. This vulnerability impacts only an Alpha level feature, the Kubernetes Gateway API. This is not the same as the Istio Gateway type (gateways.networking.istio.io), which is not vulnerable. Users are advised to upgrade to resolve this issue. Users unable to upgrade should implement any of the following which will prevent this vulnerability: Remove the gateways.gateway.networking.k8s.io CustomResourceDefinition, set PILOT_ENABLE_GATEWAY_API_DEPLOYMENT_CONTROLLER=true environment variable in Istiod, or remove CREATE permissions for gateways.gateway.networking.k8s.io objects from untrusted users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21679 β€Ό

Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts might be accidentally bypassed for ALLOW action or rejected unexpectedly for DENY action during the upgrade from 1.11 to 1.12.0/1.12.1. Istio 1.12 supports the hosts and notHosts fields in authorization policy with a new Envoy API shipped with the 1.12 data plane. A bug in the 1.12.0 and 1.12.1 incorrectly uses the new Envoy API with the 1.11 data plane. This will cause the hosts and notHosts fields to be always matched regardless of the actual value of the host header when mixing 1.12.0/1.12.1 control plane and 1.11 data plane. Users are advised to upgrade or to not mix the 1.12.0/1.12.1 control plane with 1.11 data plane if using hosts or notHosts field in authorization policy.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43269 β€Ό

In Code42 app before 8.8.0, eval injection allows an attacker to change a deviceÒ€ℒs proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for Small Business. (Incydr Professional and Enterprise are unaffected.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0277 β€Ό

Improper Access Control in Packagist microweber/microweber prior to 1.2.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0278 β€Ό

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Eleven prolific BEC scam suspects arrested in Nigeria πŸ—“οΈ

SilverTerrier brought to heel

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0281 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34600 β€Ό

Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for authorization of users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22820 β€Ό

Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45230 β€Ό

In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3866 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip prior to main.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0282 β€Ό

Code Injection in Packagist microweber/microweber prior to 1.2.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22733 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cisco's Kenna Security Research Shows the Relative Likelihood of an Organization Being Exploited πŸ•΄

A record-breaking 20,130 vulnerabilities were reported in 2021. However, only 4% pose a high risk to organizations.

πŸ“– Read

via "Dark Reading".
🦿 WAN report: Complexity continue to grow as more organizations close legacy data centers 🦿

The sixth annual report from Aryaka found that IT teams are planning to invest more in 2022 but expect more transparency and control.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Red Cross suffers cyber-attack – data of 515,000 β€˜highly vulnerable’ people exposed πŸ—“οΈ

The β€˜sophisticated’ attack was detected last week

πŸ“– Read

via "The Daily Swig".
❌ SEC Filing Reveals Fortune 500 Firm Targeted in Ransomware Attack ❌

The Fortune 500 integrated services company confirmed a β€˜systems intrusion’ that occurred in late December and is still under investigation in an SEC filing.

πŸ“– Read

via "Threat Post".