πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-46315 β€Ό

Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicoius users can use this vulnerability to use "\ " or backticks in the shell metacharacters in the ssid0 or ssid1 parameters to cause arbitrary command execution. Since CVE-2019-17510 vulnerability has not been patched and improved www/hnap1/control/setwizardconfig.php, can also use line breaks and backquotes to bypass.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25313 β€Ό

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22922 β€Ό

TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25315 β€Ό

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25314 β€Ό

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46108 β€Ό

D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Lagging behind? New study highlights weaknesses in open source patch process πŸ—“οΈ

Patch delays create a β€˜window of opportunity’ for observant attackers

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0660 β€Ό

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

πŸ“– Read

via "National Vulnerability Database".
❌ Iranian State Broadcaster Clobbered by β€˜Clumsy, Buggy’ Code ❌

Researchers said a Jan. 27 attack that aired footage of opposition leaders calling for assassination of Iran’s Supreme Leader was a clumsy and unsophisticated wiper attack.

πŸ“– Read

via "Threat Post".
❌ Severe WordPress Plug-In UpdraftPlus Bug Threatens Backups ❌

An oversight in a WordPress plug-in exposes PII and authentication data to malicious insiders.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers πŸ—“οΈ

Patch now to protect, say researchers

πŸ“– Read

via "The Daily Swig".
πŸ•΄ If the Cloud Is More Secure, Then Why Is Everything Still Broken? πŸ•΄

The sooner we discover sources of risk, the better equipped we will be to create effective mitigations for them.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ransomware Adds New Wrinkle in Russian Cybercrime Market πŸ•΄

Government crackdowns may destabilize Russian crime rings and strengthen their ties to Chinese allies.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-0664 β€Ό

Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25299 β€Ό

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25298 β€Ό

This affects the package sprinfall/webcc before 0.3.0. It is possible to traverse directories to fetch arbitrary files from the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0451 β€Ό

Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to example.com with authorization header and it redirects to an attackers site, they might not expect attacker site to receive authorization header. We recommend updating the Dart SDK to version 2.16.0 or beyond.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46372 β€Ό

Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0631 β€Ό

Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep70: Bitcoin, billing blunders, and 0-day after 0-day after 0-day [Podcast + Transcript] ⚠

Latest episode - listen and learn!

πŸ“– Read

via "Naked Security".
πŸ•΄ Enterprises Look Beyond Antivirus Software for Remote Workers πŸ•΄

Priorities are shifting, with growing emphasis on endpoint detection and response (EDR) software and multifactor authentication (MFA), a recent survey of IT professionals shows.

πŸ“– Read

via "Dark Reading".