πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Ransomware with a difference: β€œDerestrict your software, or else!” ⚠

"Change your code to improve cryptomining"... or we'll dump 1TB of stolen secrets.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-0819 β€Ό

Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24306 β€Ό

Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25634 β€Ό

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23779 β€Ό

Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24447 β€Ό

An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24305 β€Ό

Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  GRAudit Grep Auditing Tool 3.4 πŸ› 

Graudit is a simple script and signature sets that allows you to find potential security flaws in source code using the GNU utility, grep. It's comparable to other static analysis applications like RATS, SWAAT, and flaw-finder while keeping the technical requirements to a minimum and being very flexible.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ 3 Ways to Expand Gender Diversity in Cybersecurity πŸ•΄

Why this is important: A business that surrounds itself with the same kind of people who work on the same projects will not generate new or original ideas.

πŸ“– Read

via "Dark Reading".
πŸ‘Ž1
β™ŸοΈ Conti Ransomware Group Diaries, Part II: The Office β™ŸοΈ

Earlier this week, a Ukrainian security researcher leaked almost two years’ worth of internal chat logs from Conti, one of the more rapacious and ruthless ransomware gangs in operation today. Tuesday’s story examined how Conti dealt with its own internal breaches and attacks from private security firms and governments. In Part II of this series we’ll explore what it’s like to work for Conti, as described by the Conti employees themselves.

πŸ“– Read

via "Krebs on Security".
πŸ‘1
πŸ•΄ Protecting Field Programmable Gate Arrays From Attacks πŸ•΄

FPGAs can be part of physical systems in the aerospace, medical, or industrial fields, so a security compromise can be potentially serious.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-25016 β€Ό

Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-43070 β€Ό

Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22350 β€Ό

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38996 β€Ό

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213076.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Companies' Code Leaking More Passwords and Secrets πŸ•΄

Software code pushed to online code repositories exposed twice as many secrets compared to last year, putting organizations' security at risk.

πŸ“– Read

via "Dark Reading".
πŸ” Senate Passes Act That Would Require Disclosing Cyberattacks πŸ”

The Senate has passed legislation that among other requirements, would require critical infrastructure entities to report to the federal government when they are hacked.

πŸ“– Read

via "".
πŸ•΄ Researchers Devise Attack for Stealing Data During Homomorphic Encryption πŸ•΄

A vulnerability in a Microsoft crypto library gives attackers a way to figure out what data is being encrypted in lockpicker-like fashion.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-38268 β€Ό

The Dynamic Data Mapping module in Liferay Portal through v7.3.6 and Liferay DXP through v7.3 incorrectly sets default permissions for site members, allowing authenticated attackers to add and duplicate forms via the UI or the API.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23878 β€Ό

seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23640 β€Ό

Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a patch. There is no known workaround.

πŸ“– Read

via "National Vulnerability Database".