πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24924 β€Ό

An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45386 β€Ό

tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24926 β€Ό

Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39664 β€Ό

In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure when parsing an APK file with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-203938029

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22798 β€Ό

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a Network is sniffed. Affected Product: Conext? ComBox (All Versions)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23597 β€Ό

This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the application. **Note:** This is a bypass of CVE-2020-8136 (https://security.snyk.io/vuln/SNYK-JS-FASTIFYMULTIPART-1290382).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24927 β€Ό

Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39666 β€Ό

In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-204445255

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23427 β€Ό

PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39671 β€Ό

In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-206718630

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Google Project Zero hails dramatic acceleration in security bug remediation πŸ—“οΈ

Researchers credit greater transparency and responsible disclosure policies for improvements in the patching process

πŸ“– Read

via "The Daily Swig".
❌ Cybercrooks Frame Targets by Planting Fabricated Digital Evidence ❌

The β€˜ModifiedElephant’ threat actors are technically unimpressive, but they’ve evaded detection for a decade, hacking human rights advocates' systems with dusty old keyloggers and off-the-shelf RATs.

πŸ“– Read

via "Threat Post".
πŸ•΄ Google Paid Record $8.7 Million to Bug Hunters in 2021 πŸ•΄

Company's Chrome and Android technologies continued to be target-rich environments for security researchers from around the world.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-23555 β€Ό

The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22766 β€Ό

Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health information (ePHI) or other sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24975 β€Ό

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20001 β€Ό

It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26728 β€Ό

A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical MQTT-Related Bugs Open Industrial Networks to RCE Via Moxa ❌

A collection of five security vulnerabilities with a collective CVSS score of 10 out of 10 threaten critical infrastructure environments that use Moxa MXview.

πŸ“– Read

via "Threat Post".
πŸ•΄ Aviatrix Enhances Secure Cloud Networking with Network Behavior Analytics πŸ•΄

New capabilities added to Aviatrix ThreatIQ improve enterprise security posture to reduce business risk.

πŸ“– Read

via "Dark Reading".
πŸ•΄ DDoS Attacks on a Tear in Q4 2021 πŸ•΄

New data from Kaspersky shows distributed denial-of-service attacks increased by more than 50% in the fourth quarter of last year compared with the third quarter.

πŸ“– Read

via "Dark Reading".