πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24515 β€Ό

Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24506, CVE-2022-24518, CVE-2022-24519.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24518 β€Ό

Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24506, CVE-2022-24515, CVE-2022-24519.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22007 β€Ό

HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22006, CVE-2022-23301, CVE-2022-24452, CVE-2022-24453, CVE-2022-24456.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21990 β€Ό

Remote Desktop Client Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-23285.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23283 β€Ό

Windows ALPC Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-23287, CVE-2022-24505.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24470 β€Ό

Azure Site Recovery Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24467, CVE-2022-24468, CVE-2022-24471, CVE-2022-24517, CVE-2022-24520.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36777 β€Ό

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21977 β€Ό

Media Foundation Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-22010.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24509 β€Ό

Microsoft Office Visio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24461, CVE-2022-24510.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23291 β€Ό

Windows DWM Core Library Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-23288.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23278 β€Ό

Microsoft Defender for Endpoint Spoofing Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24462 β€Ό

Microsoft Word Security Feature Bypass Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24526 β€Ό

Visual Studio Code Spoofing Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23281 β€Ό

Windows Common Log File System Driver Information Disclosure Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24469 β€Ό

Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24506, CVE-2022-24515, CVE-2022-24518, CVE-2022-24519.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24525 β€Ό

Windows Update Stack Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24508 β€Ό

Windows SMBv3 Client/Server Remote Code Execution Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ Palo Alto Networks Introduces Prisma Cloud Supply Chain Security πŸ•΄

Threat modeling visualization, code repository scanning, and pipeline configuration analysis help prioritize vulnerabilities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 10 Signs of a Poor Security Leader πŸ•΄

Weak leadership can demotivate and demoralize the security workforce. Here's what to look out for.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Bitdefender Launches New Password Manager Solution for Consumers πŸ•΄

Simplifies the creation and management of secure passwords for all online accounts across multiple platforms including mobile.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24919 β€Ό

An authenticated user can create a link with reflected Javascript code inside it for graphsΓƒΒ’Γ’β€šΒ¬Γ’β€žΒ’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.

πŸ“– Read

via "National Vulnerability Database".