βΌ CVE-2022-0348 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.π Read
via "National Vulnerability Database".
π΄ Log4j Proved Public Disclosure Still Helps Attackers π΄
π Read
via "Dark Reading".
Disclosure also puts organizations in the awkward position of trying to mitigate a vulnerability without something like a vendor patch to do the job.π Read
via "Dark Reading".
Dark Reading
Log4j Proved Public Disclosure Still Helps Attackers
Disclosure also puts organizations in the awkward position of trying to mitigate a vulnerability without something like a vendor patch to do the job.
ποΈ Apple pays out $100k bounty for Safari webcam hack that imperiled victimsβ online accounts ποΈ
π Read
via "The Daily Swig".
Gatekeeper defenses prove no match for uXSS attackπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Apple pays out $100k bounty for Safari webcam hack that imperiled victimsβ online accounts
Gatekeeper defenses prove no match for uXSS attack
π΄ Censys Completes $35 Million Series B Funding Round Led by Intel Capital π΄
π Read
via "Dark Reading".
Also names Brad Brooks as new CEO.π Read
via "Dark Reading".
Dark Reading
Censys Completes $35 Million Series B Funding Round Led by Intel Capital
Also names Brad Brooks as new CEO.
π΄ Barracuda Expands Email and Endpoint Protection Capabilities in MSP Security Offerings π΄
π Read
via "Dark Reading".
Barracuda enhances SKOUT Managed XDR offering via new integration with Barracuda Email Protection and alliance with SentinelOne for endpoint protection.π Read
via "Dark Reading".
Dark Reading
Barracuda Expands Email and Endpoint Protection Capabilities in MSP Security Offerings
Barracuda enhances SKOUT Managed XDR offering via new integration with Barracuda Email Protection and alliance with SentinelOne for endpoint protection.
π¦Ώ Data Privacy Day: Security experts' tips for 2022 π¦Ώ
π Read
via "Tech Republic".
Data Privacy Day is a day to focus on best practices for ensuring private data remains that way. Learn insights and tips from security experts on the front lines.π Read
via "Tech Republic".
TechRepublic
Data Privacy Day: Security experts' tips for 2022
Data Privacy Day is a day to focus on best practices for ensuring private data remains that way. Learn insights and tips from security experts on the front lines.
π¦Ώ Patch now: A newly discovered critical Linux vulnerability probably affects your systems π¦Ώ
π Read
via "Tech Republic".
Dubbed PwnKit, it's been sitting in a user policy module used in Linux distros for over a decade and can be used by anyone to gain root privileges. Here's what you can do to protect your systems.π Read
via "Tech Republic".
TechRepublic
Patch now: A newly discovered critical Linux vulnerability probably affects your systems
Dubbed PwnKit, it's been sitting in a user policy module used in Linux distros for over a decade and can be used by anyone to gain root privileges. Here's what you can do to protect your systems.
π΄ With Cloud the Norm, Insiders Are Everywhere β and Pose Greater Risk π΄
π Read
via "Dark Reading".
After companies accelerated their adoption of cloud infrastructure, remote workers are now insiders and pose significant risks, and costs, to companies.π Read
via "Dark Reading".
Dark Reading
With Cloud the Norm, Insiders Are Everywhere β and Pose Greater Risk
After companies accelerated their adoption of cloud infrastructure, remote workers are now insiders and pose significant risks, and costs, to companies.
βΌ CVE-2021-46065 βΌ
π Read
via "National Vulnerability Database".
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46088 βΌ
π Read
via "National Vulnerability Database".
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46097 βΌ
π Read
via "National Vulnerability Database".
Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_logπ Read
via "National Vulnerability Database".
βΌ CVE-2021-46102 βΌ
π Read
via "National Vulnerability Database".
From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable "addr" via "addr = (sym.st_value + refd_pa) as u64";π Read
via "National Vulnerability Database".
βΌ CVE-2021-46377 βΌ
π Read
via "National Vulnerability Database".
There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUserπ Read
via "National Vulnerability Database".
π΄ Security Service Edge: 4 Core Tenets for Your SASE Journey π΄
π Read
via "Dark Reading".
Historically we've held network conversations to address security problems, but that doesn't work in a cloud-based world.π Read
via "Dark Reading".
Dark Reading
Security Service Edge: 4 Core Tenets for Your SASE Journey
Historically we've held network conversations to address security problems, but that doesn't work in a cloud-based world.
βΌ CVE-2021-46519 βΌ
π Read
via "National Vulnerability Database".
Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_array_length at src/mjs_array.c.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46507 βΌ
π Read
via "National Vulnerability Database".
Jsish v3.5.0 was discovered to contain a stack overflow via Jsi_LogMsg at src/jsiUtils.c.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46505 βΌ
π Read
via "National Vulnerability Database".
Jsish v3.5.0 was discovered to contain a stack overflow via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x5b1e5.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46515 βΌ
π Read
via "National Vulnerability Database".
There is an Assertion `mjs_stack_size(&mjs->scopes) >= scopes_len' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46517 βΌ
π Read
via "National Vulnerability Database".
There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46495 βΌ
π Read
via "National Vulnerability Database".
Jsish v3.5.0 was discovered to contain a heap-use-after-free via DeleteTreeValue in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).π Read
via "National Vulnerability Database".
βΌ CVE-2021-46511 βΌ
π Read
via "National Vulnerability Database".
There is an Assertion `m->len >= sizeof(v)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.π Read
via "National Vulnerability Database".