πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Vulnerabilities in Cisco Small Business routers could allow unauthenticated attackers persistent access to internal networks πŸ—“οΈ

Critical security bugs inherited by multiple products

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Want to Be an Ethical Hacker? Here's Where to Begin πŸ•΄

By utilizing these resources, beginner hackers can find their specific passions within the cybersecurity space and eventually make their own mark in the ethical hacking profession.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Google Drive integration errors created SSRF flaws in multiple applications πŸ—“οΈ

Bug hunter earned $17k bounty for HelloSign bug

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-44983 β€Ό

In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep68: Bugs, scams, privacy …and fonts?! [Podcast + Transcript] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ•΄ China-Linked Group Attacked Taiwanese Financial Firms for 18 Months πŸ•΄

The Antlion group, also known as Pirate Panda and Tropic Trooper, has shifted to targeting mainly Taiwan, using custom backdoors against financial organizations.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-44886 β€Ό

In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44978 β€Ό

iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43145 β€Ό

With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46398 β€Ό

A Cross-Site Request Forgery (CSRF) vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44977 β€Ό

In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
⚠ Wormhole cryptotrading company turns over $340,000,000 to criminals ⚠

It was the best of blockchains, it was the worst of blockchains... as Charles Dickens might have said.

πŸ“– Read

via "Naked Security".
❌ Argo CD Security Bug Opens Kubernetes Cloud Apps to Attackers ❌

The popular continuous-delivery platform has a path-traversal bug (CVE-2022-24348) that could allow cyberattackers to hop from one application ecosystem to another.

πŸ“– Read

via "Threat Post".
❌ β€˜Long Live Log4Shell’: CVE-2021-44228 Not Dead Yet ❌

The ubiquitous Log4j bug will be with us for years. John Hammond, senior security researcher at Huntress, discusses what's next.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-43635 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24260 β€Ό

A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24259 β€Ό

An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24262 β€Ό

The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 2/4 πŸ”

Hacking North Korea, inside the Trickbot ransomware group, and more - catch up on the infosec news of the week with the Friday Five!

πŸ“– Read

via "".
πŸ•΄ Expert Insights: Training the Data Elephant in the AI Room πŸ•΄

Be aware of the risk of inadvertent data exposure in machine learning systems.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-29394 β€Ό

Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.

πŸ“– Read

via "National Vulnerability Database".