πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-0417 β€Ό

Heap-based Buffer Overflow in Conda vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24983 β€Ό

The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ SureMDM bug chain enabled wholesale compromise of managed devices πŸ—“οΈ

Series of flaws in MDM platform addressed in web console and Linux agent

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Mastercard Launches Global Cybersecurity Alliance Program to Further Secure The Digital Ecosystem πŸ•΄

New program helps partners accelerate growth and provide scaled delivery of critical cybersecurity and risk services.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Qualys Adds Advanced Remediation Capabilities to Minimize Vulnerability Risk πŸ•΄

Update to Qualys Cloud Platform enables organizations to fix asset misconfigurations in addition to patching to achieve comprehensive remediation.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Critical Samba flaw presents code execution threat πŸ—“οΈ

Urgent patching of file-sharing technology urged

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-38560 β€Ό

Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44746 β€Ό

UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Manager V8.9.1 and prior, Data Maintenance Tool for DT900 Series V5.3.0.0 and prior, Data Maintenance Tool for DT800 Series V4.2.0.0 and prior allows a remote attacker who can access to the internal network, the configuration information may be obtained.

πŸ“– Read

via "National Vulnerability Database".
⚠ Website operator fined for using Google Fonts β€œthe cloudy way” ⚠

Google Fonts are OK, it seems, but only if everyone keeps their own copy of the fonts they use.

πŸ“– Read

via "Naked Security".
πŸ•΄ Complexity vs. Capability: How to Bridge the Security Effectiveness Gap πŸ•΄

Consolidation and automation are among the strategies for balancing security complexity and capability.

πŸ“– Read

via "Dark Reading".
⚠ Linux kernel patches β€œperformance can be harmful” bug in video driver ⚠

This bug is fiendishly hard to exploit - but if you patch, it won't be there to exploit at all.

πŸ“– Read

via "Naked Security".
πŸ•΄ 7 Red Flags That Can Stop Your Company From Becoming a Unicorn πŸ•΄

Investors and venture capitalists share the reasons that make them turn away from investing in your security tech.

πŸ“– Read

via "Dark Reading".
❌ Samba β€˜Fruit’ Bug Allows RCE, Full Root User Access ❌

The issue in the file-sharing and interop platform also affects Red Hat, SUSE Linux and Ubuntu packages.

πŸ“– Read

via "Threat Post".
❌ The Account Takeover Cat-and-Mouse Game ❌

ATO attacks are evolving. Jason Kent, hacker-in-residence at Cequence Security, discusses what new-style cyberattacks look like in the wild.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-24220 β€Ό

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24198 β€Ό

iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24196 β€Ό

iText v7.1.17 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24223 β€Ό

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24222 β€Ό

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24219 β€Ό

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24197 β€Ό

iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".