πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24198 β€Ό

iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24196 β€Ό

iText v7.1.17 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24223 β€Ό

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24222 β€Ό

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24219 β€Ό

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24197 β€Ό

iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24221 β€Ό

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24218 β€Ό

An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46093 β€Ό

eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.

πŸ“– Read

via "National Vulnerability Database".
❌ Unpatched Security Bugs in Medical Wearables Allow Patient Tracking, Data Theft ❌

Rising critical unpatched vulnerabilities and a lack of encryption leave medical device data defenseless, researcher warn.

πŸ“– Read

via "Threat Post".
πŸ•΄ Digital Shadows Launches New Vulnerability Intelligence Module πŸ•΄

New capability simplifies challenge of prioritizing CVEs for faster triage and remediation.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Disclosure, Panic, Patch: Can We Do Better? πŸ•΄

Companies struggle to understand the extent to which they are affected by vulnerabilities in open source software, but security specialists and maintainers are striving to secure the ecosystem.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Forescout Acquires CyberMDX to Expand Healthcare Cybersecurity Focus πŸ•΄

Acquisition adds Internet of Medical Things (IoMT) expertise to Forescout’s IT, IoT, and OT coverage.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ping Identity Launches PingOne DaVinci πŸ•΄

No-code identity orchestration service enables organizations to design better user experiences with drag-and-drop simplicity.

πŸ“– Read

via "Dark Reading".
πŸ•΄ ShiftLeft CORE 'Velocity Update' Streamlines Triage, Automates Build Security Controls πŸ•΄

New features empower developers and AppSec teams to streamline the triage process and automate security controls.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Vectra Acquires Siriux Security Technologies to Extend Leadership in Identity and SaaS Threat Management πŸ•΄

The acquisition positions Vectra to help customers securely configure and detect active threats in cloud identity and SaaS applications, including Microsoft Azure AD and Microsoft 365.

πŸ“– Read

via "Dark Reading".
❌ FBI: Use a Burner Phone at the Olympics ❌

The warning follows a Citizen Lab report that found the official, mandatory app has an encryption flaw that "can be trivially sidestepped." Besides burners, here are more tips on staying cyber-safe at the Games.

πŸ“– Read

via "Threat Post".
πŸ•΄ Nucleus Security Forms Strategic Partnership with Mandiant πŸ•΄

Intent is to enhance vulnerability management programs with operationalized threat intelligence.

πŸ“– Read

via "Dark Reading".
πŸ•΄ ThycoticCentrify Renamed Delinea πŸ•΄

Privileged access management vendor rebrands.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Secure Web Browsers Tackle Ransomware, Insider Threat in Enterprises πŸ•΄

Enterprise security teams can use secure web browsers to apply controls and governance to cloud applications and customer data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42638 β€Ό

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.

πŸ“– Read

via "National Vulnerability Database".