πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-0295 β€Ό

Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25033 β€Ό

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0301 β€Ό

Heap buffer overflow in DevTools in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24874 β€Ό

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0305 β€Ό

Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25050 β€Ό

The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0569 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor in Packagist snipe/snipe-it prior to v5.3.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24110 β€Ό

Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ New Zealand government mandates bug reporting process for federal agencies πŸ—“οΈ

Researchers can report vulnerabilities on a β€˜no blame’ basis

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Ransomware Threat Intel: You're Soaking In It! πŸ•΄

Organizations need to improve their ability to detect and prevent emerging ransomware attacks.

πŸ“– Read

via "Dark Reading".
⚠ Power company pays out $3 trillion compensation to astonished customer ⚠

More money than the UK's economy produces in a year!

πŸ“– Read

via "Naked Security".
πŸ•΄ Could Biology Hold the Clue to Better Cybersecurity? πŸ•΄

Sophisticated malware attacks underscore the need for a more dynamic security framework, inspired by biological concepts.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-45420 β€Ό

** UNSUPPORTED WHEN ASSIGNED ** Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45421 β€Ό

** UNSUPPORTED WHEN ASSIGNED ** Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or replaced.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24686 β€Ό

HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ (ISC)Β² to Pilot Online Proctored Exams for CISSP in U.S., U.K. and Singapore πŸ•΄

Second pilot program will assess feasibility and security of offering online exams to increase global accessibility for certification candidates.

πŸ“– Read

via "Dark Reading".
πŸ•΄ LogRhythm Unveils New Brand Identity πŸ•΄

Announcement comes in advance of new technology offerings in 2022.

πŸ“– Read

via "Dark Reading".
πŸ•΄ One Identity Enhances Unified Identity Security Platform with CIEM, Application Governance and Teams Modules πŸ•΄

Plans to further advance vision for end-to-end identity security.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Missouri prosecutor declines to file charges over β€˜hacker’ allegation against reporter πŸ—“οΈ

Relief as controversial charges dropped tempered by fears about chilling effect

πŸ“– Read

via "The Daily Swig".
❌ Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack ❌

The vendor issued an emergency fix on Sunday, and eCommerce websites should update ASAP to avoid Magecart card-skimming attacks and other problems.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-46371 β€Ό

antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.

πŸ“– Read

via "National Vulnerability Database".