🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2022-24263

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

📖 Read

via "National Vulnerability Database".
CVE-2022-24264

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

📖 Read

via "National Vulnerability Database".
CVE-2022-23872

Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/configure.php via the parameter footer_info.

📖 Read

via "National Vulnerability Database".
CVE-2022-24265

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

📖 Read

via "National Vulnerability Database".
CVE-2022-24266

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

📖 Read

via "National Vulnerability Database".
🕴 Security Service Edge Boosters Form New Forum to Encourage Adoption 🕴

IT leaders who formed the SSE Forum say the technology offers cloud-forward security for modern workplaces.

📖 Read

via "Dark Reading".
🕴 Mandiant: One in 7 Ransomware Extortion Attacks Expose OT Data 🕴

Analysis of 'shaming site' data dumps found sensitive documentation from OT organizations including oil & gas.

📖 Read

via "Dark Reading".
👍1
CVE-2021-46662

MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.

📖 Read

via "National Vulnerability Database".
👍1
CVE-2021-46667

MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

📖 Read

via "National Vulnerability Database".
CVE-2021-46664

MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

📖 Read

via "National Vulnerability Database".
CVE-2021-46669

MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.

📖 Read

via "National Vulnerability Database".
CVE-2021-46665

MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.

📖 Read

via "National Vulnerability Database".
CVE-2021-46666

MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.

📖 Read

via "National Vulnerability Database".
CVE-2021-3534

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-34981. Reason: This candidate is a reservation duplicate of CVE-2021-34981. Notes: All CVE users should reference CVE-2021-34981 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

📖 Read

via "National Vulnerability Database".
CVE-2021-46663

MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.

📖 Read

via "National Vulnerability Database".
CVE-2021-46661

MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).

📖 Read

via "National Vulnerability Database".
CVE-2021-46668

MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.

📖 Read

via "National Vulnerability Database".
🕴 Coalition Launches Executive Risks Products With Personalized Risk Assessment 🕴

Coalition now offering Directors & Officers (D&O) and Employment Practices Liability (EPL) with new tools and features to all broker partners.

📖 Read

via "Dark Reading".
🕴 Cymulate Launches Service to Augment In-House Security Teams 🕴

Amplify bolsters organizations with limited resources to optimize their security posture.

📖 Read

via "Dark Reading".
Living Off the Land: How to Defend Against Malicious Use of Legitimate Utilities

LOLBins help attackers become invisible to security platforms. Uptycs provides a rundown of the most commonly abused native utilities for Windows, Linux and macOS – and advice for protection.

📖 Read

via "Threat Post".
🗓️ Decryption key released for DeadBolt ransomware after QNAP NAS devices infected 🗓️

Tool enables decryption key to work after forced firmware update rendered it useless

📖 Read

via "The Daily Swig".