πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-46320 β€Ό

In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an initializer has finished running it can never be re-executed. However, an exception put in place to support multiple inheritance made reentrancy possible, breaking the expectation that there is a single execution.

πŸ“– Read

via "National Vulnerability Database".
❌ Attackers Target Intuit Users by Threatening to Cancel Tax Accounts ❌

The usual tax-season barrage of cybercriminal activity is already underway with a phishing campaign impersonating the popular accounting and tax-filing software.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Vulnerabilities in Cisco Small Business routers could allow unauthenticated attackers persistent access to internal networks πŸ—“οΈ

Critical security bugs inherited by multiple products

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Want to Be an Ethical Hacker? Here's Where to Begin πŸ•΄

By utilizing these resources, beginner hackers can find their specific passions within the cybersecurity space and eventually make their own mark in the ethical hacking profession.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Google Drive integration errors created SSRF flaws in multiple applications πŸ—“οΈ

Bug hunter earned $17k bounty for HelloSign bug

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-44983 β€Ό

In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep68: Bugs, scams, privacy …and fonts?! [Podcast + Transcript] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ•΄ China-Linked Group Attacked Taiwanese Financial Firms for 18 Months πŸ•΄

The Antlion group, also known as Pirate Panda and Tropic Trooper, has shifted to targeting mainly Taiwan, using custom backdoors against financial organizations.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-44886 β€Ό

In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44978 β€Ό

iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43145 β€Ό

With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46398 β€Ό

A Cross-Site Request Forgery (CSRF) vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44977 β€Ό

In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
⚠ Wormhole cryptotrading company turns over $340,000,000 to criminals ⚠

It was the best of blockchains, it was the worst of blockchains... as Charles Dickens might have said.

πŸ“– Read

via "Naked Security".
❌ Argo CD Security Bug Opens Kubernetes Cloud Apps to Attackers ❌

The popular continuous-delivery platform has a path-traversal bug (CVE-2022-24348) that could allow cyberattackers to hop from one application ecosystem to another.

πŸ“– Read

via "Threat Post".
❌ β€˜Long Live Log4Shell’: CVE-2021-44228 Not Dead Yet ❌

The ubiquitous Log4j bug will be with us for years. John Hammond, senior security researcher at Huntress, discusses what's next.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-43635 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24260 β€Ό

A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24259 β€Ό

An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24262 β€Ό

The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 2/4 πŸ”

Hacking North Korea, inside the Trickbot ransomware group, and more - catch up on the infosec news of the week with the Friday Five!

πŸ“– Read

via "".