βΌ CVE-2022-24327 βΌ
π Read
via "National Vulnerability Database".
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24332 βΌ
π Read
via "National Vulnerability Database".
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24329 βΌ
π Read
via "National Vulnerability Database".
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24331 βΌ
π Read
via "National Vulnerability Database".
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24346 βΌ
π Read
via "National Vulnerability Database".
In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24337 βΌ
π Read
via "National Vulnerability Database".
In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24328 βΌ
π Read
via "National Vulnerability Database".
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24330 βΌ
π Read
via "National Vulnerability Database".
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24333 βΌ
π Read
via "National Vulnerability Database".
In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24343 βΌ
π Read
via "National Vulnerability Database".
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24336 βΌ
π Read
via "National Vulnerability Database".
In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24344 βΌ
π Read
via "National Vulnerability Database".
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24335 βΌ
π Read
via "National Vulnerability Database".
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24342 βΌ
π Read
via "National Vulnerability Database".
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.π Read
via "National Vulnerability Database".
π΄ Top 5 Interview Questions to Ask DevOps Candidates in 2022 π΄
π Read
via "Dark Reading".
It's worthwhile to find candidates who have experience with models that embed security into their processes.π Read
via "Dark Reading".
Dark Reading
Top 5 Interview Questions to Ask DevOps Candidates in 2022
It's worthwhile to find candidates who have experience with models that embed security into their processes.
β S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast + Transcript] β
π Read
via "Naked Security".
Latest episode - listen now!π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
β Did we learn nothing from Y2K? Why are some coders still stuck on two digit numbers? β
π Read
via "Naked Security".
Calling all website coders: Y2K was then. V1H is now!π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
β 6 Cyber-Defense Steps to Take Now to Protect Your Company β
π Read
via "Threat Post".
Ransomware is getting worse, but Daniel Spicer, chief security officer at Ivanti, offers a checklist for choosing defense solutions to meet the challenge.π Read
via "Threat Post".
Threat Post
6 Cyber-Defense Steps to Take Now to Protect Your Company
Ransomware is getting worse, but Daniel Spicer, chief security officer at Ivanti, offers a checklist for choosing defense solutions to meet the challenge.
π Friday Five 2/25 π
π Read
via "".
Ransomware hits the industrial sector, behind the scenes of stalkerware network, and more - catch up on the infosec news of the week with the Friday Five!π Read
via "".
Digital Guardian
Friday Five 2/25
Ransomware hits the industrial sector, behind the scenes of a stalkerware network, and more - catch up on the infosec news of the week with the Friday Five!
βΌ CVE-2021-38993 βΌ
π Read
via "National Vulnerability Database".
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the smbcd daemon to cause a denial of service. IBM X-Force ID: 212962.π Read
via "National Vulnerability Database".
βοΈ Russia Sanctions May Spark Escalating Cyber Conflict βοΈ
π Read
via "Krebs on Security".
President Biden joined European leaders this week in enacting economic sanctions against Russia in response its military invasion of Ukraine. The West has promised tougher sanctions are coming, but experts warn these will almost certainly trigger a Russian retaliation against America and its allies, which could escalate into cyber attacks on Western financial institutions and energy infrastructure.π Read
via "Krebs on Security".
Krebsonsecurity
Russia Sanctions May Spark Escalating Cyber Conflict
President Biden joined European leaders this week in enacting economic sanctions against Russia in response its military invasion of Ukraine. The West has promised tougher sanctions are coming, but experts warn these will almost certainly trigger a Russianβ¦