πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ IT Pro News In Review: Compromised Nvidia data, protesters boycott Russian tech, Conti data breach πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ“’ OneWeb suspends satellite launch from Russian spaceport πŸ“’

The decision follows Roscosmos’ demand that the UK sell its 20% stake in OneWeb purchased in 2020

πŸ“– Read

via "ITPro".
πŸ‘1
β€Ό CVE-2022-25069 β€Ό

Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25465 β€Ό

Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25044 β€Ό

Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0849 β€Ό

Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

πŸ“– Read

via "National Vulnerability Database".
⚠ Firefox patches two in-the-wild exploits – update now! ⚠

Firefox just published a double-zero-day patch - "remote code execution" combined with "sandbox escape". Update now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-26487 β€Ό

Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allow remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic).

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-26490 β€Ό

st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0868 β€Ό

Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44748 β€Ό

A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger universal cross-site scripting through the browser. User interaction is required prior to exploitation, such as entering a malicious website to trigger the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44749 β€Ό

A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful exploitation may lead to arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0697 β€Ό

Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4199 β€Ό

Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4198 β€Ό

A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product processes and generate crashdump files. This issue affects: Bitdefender Total Security versions prior to 26.0.3.29. Bitdefender Internet Security versions prior to 26.0.3.29. Bitdefender Antivirus Plus versions prior to 26.0.3.29. Bitdefender Endpoint Security Tools versions prior to 7.2.2.92. Bitdefender VPN Standalone versions prior to 25.5.0.48.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ After a Busy December, Attacks on Log4J Vulnerability Dropped πŸ•΄

While attackers and researchers shift their attention to the next new vulnerability, security teams make sure they finish patching vulnerable Log4j versions in their applications and services .

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Utah privacy bill places tighter controls on consumer data πŸ—“οΈ

Policymakers move forward with new data privacy legislation

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why the World Needs a Global Collective Cyber Defense πŸ•΄

This sort of approach would enable cross-company and cross-sector threat information sharing, an effort that would allow companies to easily turn data into actionable insights.

πŸ“– Read

via "Dark Reading".
🀯1
β€Ό CVE-2022-0754 β€Ό

SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0755 β€Ό

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.12.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0756 β€Ό

Improper Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

πŸ“– Read

via "National Vulnerability Database".