βΌ CVE-2022-0519 βΌ
π Read
via "National Vulnerability Database".
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0523 βΌ
π Read
via "National Vulnerability Database".
Expired Pointer Dereference in NPM radare2.js prior to 5.6.2.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0520 βΌ
π Read
via "National Vulnerability Database".
Use After Free in NPM radare2.js prior to 5.6.2.π Read
via "National Vulnerability Database".
π΄ Microsoft Issues 51 CVEs for Patch Tuesday, None 'Critical' π΄
π Read
via "Dark Reading".
One publicly known flaw β an elevation-of-privilege bug in Windows Kernel β was included in the patches.π Read
via "Dark Reading".
Dark Reading
Microsoft Issues 51 CVEs for Patch Tuesday, None 'Critical'
One publicly known flaw β an elevation-of-privilege bug in Windows Kernel β was included in the patches.
βοΈ Microsoft Patch Tuesday, February 2022 Edition βοΈ
π Read
via "Krebs on Security".
Microsoft today released software updates to plug security holes in its Windows operating systems and related software. This month's relatively light patch batch is refreshingly bereft of any zero-day threats, or even scary critical vulnerabilities. But it does fix four dozen flaws, including several that Microsoft says will likely soon be exploited by malware or malcontents.π Read
via "Krebs on Security".
Krebsonsecurity
Microsoft Patch Tuesday, February 2022 Edition
Microsoft today released software updates to plug security holes in its Windows operating systems and related software. This month's relatively light patch batch is refreshingly bereft of any zero-day threats, or even scary critical vulnerabilities. But itβ¦
βΌ CVE-2022-24676 βΌ
π Read
via "National Vulnerability Database".
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.π Read
via "National Vulnerability Database".
βΌ CVE-2021-45329 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23627 βΌ
π Read
via "National Vulnerability Database".
ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`) commands. In particular, a proxy-like command sent to bot `A` targeting bot `B` has incorrectly verified user's access against bot `A` - instead of bot `B`, to which the command was originally designated. This in result allowed access to resources beyond those configured, being a security threat affecting confidentiality of other bot instances. A successful attack exploiting this bug requires a significant access granted explicitly by original owner of the ASF process prior to that, as attacker has to control at least a single bot in the process to make use of this inadequate access verification loophole. The issue is patched in ASF V5.2.2.5, V5.2.3.2 and future versions. Users are advised to update as soon as possible.π Read
via "National Vulnerability Database".
βΌ CVE-2021-45919 βΌ
π Read
via "National Vulnerability Database".
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24677 βΌ
π Read
via "National Vulnerability Database".
Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0527 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in Maven org.webjars.npm:github-com-chatwoot-chatwoot prior to 2.2.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0526 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in Maven org.webjars.npm:github-com-chatwoot-chatwoot prior to 2.2.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0525 βΌ
π Read
via "National Vulnerability Database".
Out-of-bounds Read in Homebrew mruby prior to 3.2.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24694 βΌ
π Read
via "National Vulnerability Database".
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)π Read
via "National Vulnerability Database".
βΌ CVE-2022-24682 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.π Read
via "National Vulnerability Database".
ποΈ FTC set to ramp up privacy and security rule-making activity in 2022 ποΈ
π Read
via "The Daily Swig".
Recent moves from the US government agency have laid the groundwork for significant changes to businessesβ compliance obligations, writes US attorney David Oberlyπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
FTC set to ramp up privacy and security rule-making activity in 2022
Recent moves from the US government agency have laid the groundwork for significant changes to businessesβ compliance obligations, writes US attorney David Oberly
βΌ CVE-2022-0536 βΌ
π Read
via "National Vulnerability Database".
Exposure of Sensitive Information to an Unauthorized Actor in NPM follow-redirects prior to 1.14.8.π Read
via "National Vulnerability Database".
β Ex-Gumshoe Nabs Cybercrooks with FBI Tactics β
π Read
via "Threat Post".
Crane Hassold, former FBI analyst turned director of threat intel at Abnormal Security, shares stories from his covert work with cyberattackers.π Read
via "Threat Post".
β MoleRats APT Flaunts New Trojan in Latest Cyberespionage Campaign β
π Read
via "Threat Post".
Researchers from Proofpoint have spotted a new Middle East-targeted phishing campaign that delivers a novel malware dubbed NimbleMamba.π Read
via "Threat Post".
Threat Post
MoleRats APT Flaunts New Trojan in Latest Cyberespionage Campaign
Researchers from Proofpoint have spotted a new Middle East-targeted phishing campaign that delivers a novel malware dubbed NimbleMamba.
ποΈ Cyber-attack at Vodafone Portugal knocks mobile network services offline ποΈ
π Read
via "The Daily Swig".
No customer data was accessed, company claimsπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Cyber-attack at Vodafone Portugal knocks mobile network services offline
No customer data was accessed, company claims
β Self-styled βCrocodile of Wall Streetβ arrested with husband over Bitcoin megaheist β
π Read
via "Naked Security".
The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!π Read
via "Naked Security".
Naked Security
Self-styled βCrocodile of Wall Streetβ arrested with husband over Bitcoin megaheist
The cops say theyβve recovered 80% of a $72 million cryptocoin heistβ¦ but the recovered funds alone are now worth over $4 billion!