πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-44141 β€Ό

All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0564 β€Ό

A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A successful exploit could allow the attacker to compare the response time that are returned by the affected system to determine which accounts are valid user accounts. Affected systems are only vulnerable if they have LDAP configured.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23984 β€Ό

Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22308 β€Ό

IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID: 216891.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4115 β€Ό

There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-24564 β€Ό

Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0676 β€Ό

Heap-based Buffer Overflow in NPM radare2.js prior to 5.6.4.

πŸ“– Read

via "National Vulnerability Database".
❌ NFT Investors Lose $1.7M in OpenSea Phishing Attack ❌

Attackers took advantage of a smart-contract migration to swindle 17 users.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Jaw-dropping Coinbase security bug allowed users to steal unlimited cryptocurrency πŸ—“οΈ

Researcher nets $250,000 for β€˜potentially market-nuking’ vulnerability

πŸ“– Read

via "The Daily Swig".
πŸ”₯3πŸ‘1
πŸ•΄ Hidden Costs of a Data Breach πŸ•΄

Don't consider just the initial costs. Hidden factors include remediation, revenue loss, reputational harm, national security β€” even human life.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ AirTag clone bypassed Apple’s tracking-protection features, claims researcher πŸ—“οΈ

Third-party app allegedly outperforms Find My service by detecting the DIY device

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β™ŸοΈ Report: Missouri Governor’s Office Responsible for Teacher Data Leak β™ŸοΈ

Missouri Governor Mike Parson made headlines last year when he vowed to criminally prosecute a journalist for reporting a security flaw in a state website that exposed personal information of more than 100,000 teachers. But Missouri prosecutors now say they… Read More Β»

πŸ“– Read

via "Krebs on Security".
⚠ French speakers blasted by sextortion scams with no text or links ⚠

You'd spot this one a mile away... but what about your friends or family?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-0665 β€Ό

Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  I2P 1.7.0 πŸ› 

I2P is an anonymizing network, offering a simple layer that identity-sensitive applications can use to securely communicate. All data is wrapped with several layers of encryption, and the network is both distributed and dynamic, with no trusted parties. This is the source code release version.

πŸ“– Read

via "Packet Storm Security".
⚠ WordPress backup plugin maker Updraft says β€œYou should update”… ⚠

A straight-talking bug report written in plain English by an actual expert - there's a teachable moment in this cybersecurity story!

πŸ“– Read

via "Naked Security".
β™ŸοΈ IRS: Selfies Now Optional, Biometric Data to Be Deleted β™ŸοΈ

The U.S. Internal Revenue Service (IRS) said Monday that taxpayers are no longer required to provide facial scans to create an account online at irs.gov. In lieu of providing biometric data, taxpayers can now opt for a live video interview with ID.me, the privately-held Virginia company that runs the agency's identity proofing system. The IRS also said any biometric data already shared with ID.me would be permanently deleted over the next few weeks, and any biometric data provided for new signups will be destroyed after an account is created.

πŸ“– Read

via "Krebs on Security".
πŸ‘1
❌ Xenomorph Malware Burrows into Google Play Users, No Facehugger Required ❌

Researchers discovered a new, modular banking trojan with ties to Cerberus and Alien that has the capability to become a much larger threat than it is now.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-46162 β€Ό

A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1). Affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted NEU files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15048)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0712 β€Ό

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46699 β€Ό

A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1). Affected application contains a stack based buffer overflow vulnerability while parsing specially crafted BDF files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15061)

πŸ“– Read

via "National Vulnerability Database".