πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-23627 β€Ό

ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`) commands. In particular, a proxy-like command sent to bot `A` targeting bot `B` has incorrectly verified user's access against bot `A` - instead of bot `B`, to which the command was originally designated. This in result allowed access to resources beyond those configured, being a security threat affecting confidentiality of other bot instances. A successful attack exploiting this bug requires a significant access granted explicitly by original owner of the ASF process prior to that, as attacker has to control at least a single bot in the process to make use of this inadequate access verification loophole. The issue is patched in ASF V5.2.2.5, V5.2.3.2 and future versions. Users are advised to update as soon as possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45919 β€Ό

Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24677 β€Ό

Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0527 β€Ό

Cross-site Scripting (XSS) - Stored in Maven org.webjars.npm:github-com-chatwoot-chatwoot prior to 2.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0526 β€Ό

Cross-site Scripting (XSS) - Stored in Maven org.webjars.npm:github-com-chatwoot-chatwoot prior to 2.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0525 β€Ό

Out-of-bounds Read in Homebrew mruby prior to 3.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24694 β€Ό

In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24682 β€Ό

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ FTC set to ramp up privacy and security rule-making activity in 2022 πŸ—“οΈ

Recent moves from the US government agency have laid the groundwork for significant changes to businesses’ compliance obligations, writes US attorney David Oberly

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0536 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor in NPM follow-redirects prior to 1.14.8.

πŸ“– Read

via "National Vulnerability Database".
❌ Ex-Gumshoe Nabs Cybercrooks with FBI Tactics ❌

Crane Hassold, former FBI analyst turned director of threat intel at Abnormal Security, shares stories from his covert work with cyberattackers.

πŸ“– Read

via "Threat Post".
❌ MoleRats APT Flaunts New Trojan in Latest Cyberespionage Campaign ❌

Researchers from Proofpoint have spotted a new Middle East-targeted phishing campaign that delivers a novel malware dubbed NimbleMamba.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Cyber-attack at Vodafone Portugal knocks mobile network services offline πŸ—“οΈ

No customer data was accessed, company claims

πŸ“– Read

via "The Daily Swig".
⚠ Self-styled β€œCrocodile of Wall Street” arrested with husband over Bitcoin megaheist ⚠

The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-46360 β€Ό

Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46354 β€Ό

Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0538 β€Ό

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0539 β€Ό

Cross-site Scripting (XSS) - Stored in Packagist ptrofimov/beanstalk_console prior to 1.7.14.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25939 β€Ό

In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to perform blind SSRF and send internal requests to localhost.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40837 β€Ό

A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23378 β€Ό

A Cross-Site Scripting (XSS) vulnerability exists within the 3.2.2 version of TastyIgniter. The "items%5B0%5D%5Bpath%5D" parameter of a request made to /admin/allergens/edit/1 is vulnerable.

πŸ“– Read

via "National Vulnerability Database".