πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-22724 β€Ό

A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC. Affected Product: Modicon M340 CPUs: BMXP34 (All Versions)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44204 β€Ό

Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-12891 β€Ό

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Meta says Apple's iOS privacy changes will cost it $10 billion in 2022 πŸ“’

The company's CFO suggests Google "faces a different set of restrictions" because it pays Apple to remain the default iOS search engine

πŸ“– Read

via "ITPro".
πŸ“’ KP Snacks supply chain shut down by Conti ransomware attack πŸ“’

Crippled IT systems are unable to process new orders "safely" and could be down until late-March

πŸ“– Read

via "ITPro".
πŸ“’ Picus Security joins the Microsoft Intelligent Security Association πŸ“’

The association integrates Picus’ cyber-resilience platform with Microsoft Defender for Endpoint and Microsoft Sentinel

πŸ“– Read

via "ITPro".
πŸ“’ One in seven ransomware extortion attacks leak critical OT data πŸ“’

Mandiant discovered data including usernames and passwords, IP addresses, and operator panels

πŸ“– Read

via "ITPro".
πŸ“’ Intel expands its bug bounty program with Project Circuit Breaker πŸ“’

The initiative aims to address vulnerabilities in Intel’s firmware, GPUs, hypervisors, and chipsets

πŸ“– Read

via "ITPro".
πŸ“’ Cloudflare opens $3,000 bug bounty program to the public πŸ“’

The company's previous program paid out around $212,000 over its lifetime

πŸ“– Read

via "ITPro".
πŸ“’ CISOs reveal secrets to pandemic success in critical organisations πŸ“’

The pandemic presented unique challenges for every business, but organisations tasked with delivering critical services may have worked the hardest

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-0501 β€Ό

Cross-site Scripting (XSS) - Reflected in Packagist ptrofimov/beanstalk_console prior to 1.7.12.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38172 β€Ό

perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian initially fixed this in 0.4.0-7.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0502 β€Ό

Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23206 β€Ό

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Suspected data breach at Washington State Department of Licensing πŸ—“οΈ

Agency pulls POLARIS platform offline as investigation continues

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0474 β€Ό

Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0473 β€Ό

OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface, malicious code might be exectued in the browser. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.31 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23320 β€Ό

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Name That Edge Toon: Head of the Table πŸ•΄

Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Email platform Zimbra issues hotfix for XSS vulnerability under active exploitation πŸ—“οΈ

Attackers have targeted mailboxes β€˜in multiple waves across two attack phases’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Log4j: Getting From Stopgap Remedies to Long-Term Solutions πŸ•΄

This pervasive vulnerability will require continued care and attention to fully remediate and detect permutations. Here are some ways to get started.

πŸ“– Read

via "Dark Reading".