πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Introducing Ghostbuster – AWS security tool protects against dangling elastic IP takeovers  πŸ—“οΈ

New defense against attacks that can cause more damage than other flavors of subdomain takeover

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0692 β€Ό

Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Collabfiltrator 2.1 πŸ› 

Collabfiltrator is a tool to exfiltrate blind remote code execution output over DNS via Burp Collaborator.

πŸ“– Read

via "Packet Storm Security".
πŸ›  TestSSL 3.0.7 πŸ› 

testssl.sh is a free command line tool which checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws, and much more. It is written in (pure) bash, makes only use of standard Unix utilities, openssl and last but not least bash sockets.

πŸ“– Read

via "Packet Storm Security".
πŸ›  OpenStego Free Steganography Solution 0.8.4 πŸ› 

OpenStego is a tool implemented in Java for generic steganography, with support for password-based encryption of the data. It supports plugins for various steganographic algorithms (currently, only Least Significant Bit algorithm is supported for images).

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2021-44142 β€Ό

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

πŸ“– Read

via "National Vulnerability Database".
⚠ Irony alert! PHP fixes security flaw in input validation code ⚠

What's wrong with this sequence? 1. Step into the road 2. Check if it's safe 3. Keep on walki...

πŸ“– Read

via "Naked Security".
⚠ French cybercriminals using sextortion scams with no text or links ⚠

You'd spot this one a mile away... but what about your friends or family?

πŸ“– Read

via "Naked Security".
πŸ‘1
β€Ό CVE-2022-0708 β€Ό

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44568 β€Ό

Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27796 β€Ό

A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the Ò€œuserҀ� or Ò€œfactoryҀ� account, to read the contents of any file on the filesystem utilizing one of a few available binaries.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25599 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23983 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protection & No Right Click WordPress plugin (versions <= 3.4.4).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27755 β€Ό

"Sametime Android potential path traversal vulnerability when using File class"

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27797 β€Ό

Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26256 β€Ό

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27753 β€Ό

"Sametime Android PathTraversal Vulnerability"

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24295 β€Ό

Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44141 β€Ό

All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0564 β€Ό

A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A successful exploit could allow the attacker to compare the response time that are returned by the affected system to determine which accounts are valid user accounts. Affected systems are only vulnerable if they have LDAP configured.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23984 β€Ό

Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).

πŸ“– Read

via "National Vulnerability Database".