πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-28096 β€Ό

An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44794 β€Ό

Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability to access the device information page. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23181 β€Ό

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44793 β€Ό

Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44792 β€Ό

Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could exploit this vulnerability to access the logging interface. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0348 β€Ό

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Log4j Proved Public Disclosure Still Helps Attackers πŸ•΄

Disclosure also puts organizations in the awkward position of trying to mitigate a vulnerability without something like a vendor patch to do the job.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts πŸ—“οΈ

Gatekeeper defenses prove no match for uXSS attack

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Censys Completes $35 Million Series B Funding Round Led by Intel Capital πŸ•΄

Also names Brad Brooks as new CEO.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Barracuda Expands Email and Endpoint Protection Capabilities in MSP Security Offerings πŸ•΄

Barracuda enhances SKOUT Managed XDR offering via new integration with Barracuda Email Protection and alliance with SentinelOne for endpoint protection.

πŸ“– Read

via "Dark Reading".
🦿 Data Privacy Day: Security experts' tips for 2022 🦿

Data Privacy Day is a day to focus on best practices for ensuring private data remains that way. Learn insights and tips from security experts on the front lines.

πŸ“– Read

via "Tech Republic".
🦿 Patch now: A newly discovered critical Linux vulnerability probably affects your systems 🦿

Dubbed PwnKit, it's been sitting in a user policy module used in Linux distros for over a decade and can be used by anyone to gain root privileges. Here's what you can do to protect your systems.

πŸ“– Read

via "Tech Republic".
πŸ•΄ With Cloud the Norm, Insiders Are Everywhere β€” and Pose Greater Risk πŸ•΄

After companies accelerated their adoption of cloud infrastructure, remote workers are now insiders and pose significant risks, and costs, to companies.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-46065 β€Ό

A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46088 β€Ό

Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46097 β€Ό

Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46102 β€Ό

From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable "addr" via "addr = (sym.st_value + refd_pa) as u64";

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46377 β€Ό

There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Security Service Edge: 4 Core Tenets for Your SASE Journey πŸ•΄

Historically we've held network conversations to address security problems, but that doesn't work in a cloud-based world.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-46519 β€Ό

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_array_length at src/mjs_array.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46507 β€Ό

Jsish v3.5.0 was discovered to contain a stack overflow via Jsi_LogMsg at src/jsiUtils.c.

πŸ“– Read

via "National Vulnerability Database".