πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-26779 β€Ό

Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is sent, could generate time deterministic tokens and brute force attempt to use them prior to the legitimate receiver accepting the invite. This feature is not enabled by default, the attacker is required to know or guess the project ID for the invite in addition to the invitation token, and the attacker would need to be an existing authorized user of CloudStack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27200 β€Ό

Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27218 β€Ό

Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Praetorian Launches Chariot Total Attack Life Cycle Solution πŸ•΄

New platform combines AI-based attack surface management automation with offensive security managed services to identify exposures and prioritize risk management.

πŸ“– Read

via "Dark Reading".
πŸ•΄ OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks πŸ•΄

OneLayer plans to use the funds to build its product suite.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Incognia Introduces New Location Identity Fraud Detection Tools πŸ•΄

Modules include Location Spoofing Detection, Global Mobile Address Validation, and Trusted Device Intelligence.

πŸ“– Read

via "Dark Reading".
πŸ” Utah Set to Pass U.S.'s Next Data Privacy Bill πŸ”

Utah looks like it will become the fourth U.S. state, after California, Virginia, and Colorado, to pass comprehensive consumer privacy legislation.

πŸ“– Read

via "".
❌ Cyberattacks Against Israeli Government Sites: β€˜Largest in the Country’s History’ ❌

DDoS attacks against Israel telecom companies took down government sites, sparking a temporary state of emergency.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-25488 β€Ό

Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25497 β€Ό

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45848 β€Ό

Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25494 β€Ό

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25485 β€Ό

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25486 β€Ό

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25492 β€Ό

HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25491 β€Ό

HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25489 β€Ό

Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25498 β€Ό

CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25490 β€Ό

HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25495 β€Ό

The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25493 β€Ό

HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.

πŸ“– Read

via "National Vulnerability Database".