βΌ CVE-2021-46033 βΌ
π Read
via "National Vulnerability Database".
In ForestBlog, as of 2021-12-28, File upload can bypass verification.π Read
via "National Vulnerability Database".
β Tax scam emails are alive and well as US tax season starts β
π Read
via "Naked Security".
If in doubt, don't give it out! (And don't forget that no reply is often a good reply.)π Read
via "Naked Security".
Naked Security
Tax scam emails are alive and well as US tax season starts
If in doubt, donβt give it out! (And donβt forget that no reply is often a good reply.)
π΄ Striking a Balance Between Cybersecurity Awareness and Anxiety π΄
π Read
via "Dark Reading".
Employees don't have to be paralyzed by fear to keep the company safe. They just have to understand what threats look like and how to stop them.π Read
via "Dark Reading".
Dark Reading
Striking a Balance Between Cybersecurity Awareness and Anxiety
Employees don't have to be paralyzed by fear to keep the company safe. They just have to understand what threats look like and how to stop them.
π΄ 8 Security Startups to Watch in 2022 π΄
π Read
via "Dark Reading".
Cloud security, API security, and incident response are among the issues up-and-coming security companies are working on.π Read
via "Dark Reading".
Dark Reading
8 Security Startups to Watch in 2022
Cloud security, API security, and incident response are among the issues up-and-coming security companies are working on.
β New MacOS Malware βDazzleSpyβ Used in Watering-Hole Attacks β
π Read
via "Threat Post".
A pro-democracy Hong Kong site was used to launch watering-hole attacks that planted a new macOS backdoor that researchers dubbed DazzleSpy.π Read
via "Threat Post".
Threat Post
MacOS Malware βDazzleSpyβ Used in Watering-Hole Attacks
A pro-democracy Hong Kong site was used to launch watering-hole attacks that planted a powerful macOS backdoor that researchers dubbed DazzleSpy.
βΌ CVE-2022-0351 βΌ
π Read
via "National Vulnerability Database".
Access of Memory Location Before Start of Buffer in Conda vim prior to 8.2.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39031 βΌ
π Read
via "National Vulnerability Database".
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.π Read
via "National Vulnerability Database".
β Cyberattacks on Squid Game Minecraft Tourney Take Down Andorraβs Internet β
π Read
via "Threat Post".
Some of the bursts of traffic reached up to 10Gbps, reports noted, overwhelming the country's only ISP, and crippling Andorran Squidcraft gamers along with the rest of the population.π Read
via "Threat Post".
Threat Post
Cyberattacks on Squid Game Minecraft Tourney Take Down Andorraβs Internet
Some of the bursts of traffic reached up to 10Gbps, reports noted, overwhelming the country's only ISP, and crippling Andorran Squidcraft gamers along with the rest of the population.
β Ozzy Osbourne NFTs Used to Bite Off Chunk of Crypto Coin β
π Read
via "Threat Post".
A discarded Discord vanity URL for CryptoBatz was hijacked by cybercriminals to drain cryptocurrency wallets.π Read
via "Threat Post".
Threat Post
Ozzy Osbourne NFTs Used to Bite Off Chunk of Crypto Coin
A discarded Discord vanity URL for CryptoBatz was hijacked by cybercriminals to drain cryptocurrency wallets.
β Segway Hit by Magecart Attack Hiding in a Favicon β
π Read
via "Threat Post".
Visitors who shopped on the company's eCommerce website in January will likely find their payment-card data heisted, researchers warned.π Read
via "Threat Post".
Threat Post
Segway Hit by Magecart Attack Hiding in a Favicon
Visitors who shopped on the company's eCommerce website in January will likely find their payment-card data heisted, researchers warned.
βΌ CVE-2022-0333 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23020 βΌ
π Read
via "National Vulnerability Database".
On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.π Read
via "National Vulnerability Database".
βΌ CVE-2021-45729 βΌ
π Read
via "National Vulnerability Database".
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23009 βΌ
π Read
via "National Vulnerability Database".
On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-IP devices managed by the same BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0332 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22789 βΌ
π Read
via "National Vulnerability Database".
Charactell - FormStorm Enterprise Account takeover Γ’β¬β An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23024 βΌ
π Read
via "National Vulnerability Database".
On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.π Read
via "National Vulnerability Database".
βΌ CVE-2021-4133 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23011 βΌ
π Read
via "National Vulnerability Database".
On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23026 βΌ
π Read
via "National Vulnerability Database".
On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23019 βΌ
π Read
via "National Vulnerability Database".
On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.π Read
via "National Vulnerability Database".