πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-26490 β€Ό

st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0868 β€Ό

Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44748 β€Ό

A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger universal cross-site scripting through the browser. User interaction is required prior to exploitation, such as entering a malicious website to trigger the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44749 β€Ό

A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful exploitation may lead to arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0697 β€Ό

Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4199 β€Ό

Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4198 β€Ό

A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product processes and generate crashdump files. This issue affects: Bitdefender Total Security versions prior to 26.0.3.29. Bitdefender Internet Security versions prior to 26.0.3.29. Bitdefender Antivirus Plus versions prior to 26.0.3.29. Bitdefender Endpoint Security Tools versions prior to 7.2.2.92. Bitdefender VPN Standalone versions prior to 25.5.0.48.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ After a Busy December, Attacks on Log4J Vulnerability Dropped πŸ•΄

While attackers and researchers shift their attention to the next new vulnerability, security teams make sure they finish patching vulnerable Log4j versions in their applications and services .

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Utah privacy bill places tighter controls on consumer data πŸ—“οΈ

Policymakers move forward with new data privacy legislation

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why the World Needs a Global Collective Cyber Defense πŸ•΄

This sort of approach would enable cross-company and cross-sector threat information sharing, an effort that would allow companies to easily turn data into actionable insights.

πŸ“– Read

via "Dark Reading".
🀯1
β€Ό CVE-2022-0754 β€Ό

SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0755 β€Ό

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.12.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0756 β€Ό

Improper Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical Firefox Zero-Day Bugs Allow RCE, Sandbox Escape ❌

Both vulnerabilities are use-after-free issues in Mozilla's popular web browser.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Fresh flaws in Facebook Canvas earn bug bounty hunter a second payday πŸ—“οΈ

Next-level account takeover

πŸ“– Read

via "The Daily Swig".
❌ Nvidia’s Stolen Code-Signing Certs Used to Sign Malware ❌

Nvidia certificates are being used to sign malware, enabling malicious programs to pose as legitimate and slide past security safeguards on Windows machines.

πŸ“– Read

via "Threat Post".
πŸ•΄ Industrial Systems See More Vulnerabilities, Greater Threat πŸ•΄

The makers of operational technology and connected devices saw reported vulnerabilities grow by half in 2021, but other trends may be more disturbing.

πŸ“– Read

via "Dark Reading".
❌ Samsung Confirms Lapsus$ Ransomware Hit, Source Code Leak ❌

The move comes just a week after GPU-maker NVIDIA was hit by Lapsus$ and every employee credential was leaked.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-38989 β€Ό

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22351 β€Ό

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38988 β€Ό

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212950.

πŸ“– Read

via "National Vulnerability Database".