πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Website operator fined for using Google Fonts β€œthe cloudy way” ⚠

Google Fonts are OK, it seems, but only if everyone keeps their own copy of the fonts they use.

πŸ“– Read

via "Naked Security".
❌ Apple Pays $100.5K Bug Bounty for Mac Webcam Hack ❌

The researcher found that he could gain unauthorized camera access via a shared iCloud document that could also "hack every website you've ever visited."

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-42635 β€Ό

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44114 β€Ό

Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execution via create user function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42631 β€Ό

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Number of GDPR Fines Rose 7x in 2021 πŸ”

The cost is skewed by massive fines but a new survey shows there was still a steady increase in the number of GDPR fines across the EU last year.

πŸ“– Read

via "".
πŸ•΄ Aggressive BlackCat Ransomware on the Rise πŸ•΄

The cybercriminals behind the malware claim to have compromised more than a dozen companies; they have aggressively outed victims and purportedly paid a significant share of ransoms back to affiliates.

πŸ“– Read

via "Dark Reading".
❌ Public Exploit Released for Windows 10 Bug ❌

The vulnerability affects all unpatched Windows 10 versions following a messy Microsoft January update.

πŸ“– Read

via "Threat Post".
πŸ•΄ BlackBerry Agrees to Sell Legacy Patents for $600M πŸ•΄

It has entered into a patent sale agreement with Catapult IP Innovations.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-21659 β€Ό

Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Users are advised to upgrade to version 3.4.4 as soon as possible. There are no known workarounds for this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24263 β€Ό

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24264 β€Ό

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23872 β€Ό

Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/configure.php via the parameter footer_info.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24265 β€Ό

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24266 β€Ό

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Security Service Edge Boosters Form New Forum to Encourage Adoption πŸ•΄

IT leaders who formed the SSE Forum say the technology offers cloud-forward security for modern workplaces.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Mandiant: One in 7 Ransomware Extortion Attacks Expose OT Data πŸ•΄

Analysis of 'shaming site' data dumps found sensitive documentation from OT organizations including oil & gas.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2021-46662 β€Ό

MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-46667 β€Ό

MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46664 β€Ό

MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46669 β€Ό

MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.

πŸ“– Read

via "National Vulnerability Database".