πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25354 β€Ό

The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-28273](https://security.snyk.io/vuln/SNYK-JS-SETIN-1048049)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45794 β€Ό

Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23556 β€Ό

The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes it possible for a malicious user to run an arbitrary command via the d-bus method. **Note:** Exploitation requires the user to have installed another malicious program that will be able to send dbus signals or run terminal commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0749 β€Ό

This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23771 β€Ό

This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype. **Note:** This vulnerability derives from an incomplete fix in [SNYK-JS-NOTEVIL-608878](https://security.snyk.io/vuln/SNYK-JS-NOTEVIL-608878).

πŸ“– Read

via "National Vulnerability Database".
❌ Reporting Mandates to Clear Up Feds’ Hazy Look into Threat Landscape – Podcast ❌

It’s about time, AttackIQ’s Jonathan Reiber said about 24H/72H report deadlines mandated in the new spending bill. As it is, visibility into adversary behavior has been muck.

πŸ“– Read

via "Threat Post".
❌ Misconfigured Firebase Databases Exposing Data in Mobile Apps ❌

Five percent of the databases are vulnerable to threat actors: It's a gold mine of exploit opportunity in thousands of mobile apps, researchers say.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Downdetector: How the popular site outage tracker is helping to improve web security πŸ—“οΈ

β€˜Minutes matter, and being able to get that additional feed can give infosec teams the edge’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Stopping Russian Cyberattacks at Their Source πŸ•΄

Step up training with cybersecurity drills, teach how to avoid social engineering traps, share open source monitoring tools, and make multifactor authentication the default.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-44906 β€Ό

Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25364 β€Ό

In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute malicious code as part of a build. As of 2021.4.2, the built-in build cache is inaccessible-by-default, requiring explicit configuration of its access-control settings before it can be used. (Remote build cache nodes are unaffected as they are inaccessible-by-default.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26503 β€Ό

Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24759 β€Ό

`@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` before 4.1.2 and 5.0.3 does not correctly validate signatures during the handshake process. This may allow a man-in-the-middle to pose as other peers and get those peers banned. Users should upgrade to version 4.1.2 or 5.0.3 to receive a patch. There are currently no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-15591 β€Ό

fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26526 β€Ό

Anaconda Anaconda3 through 2021.11.0.0 and Miniconda3 through 11.0.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable. Thus, for example, local users can gain privileges by placing a Trojan horse file into that directory. (This problem can only happen in a non-default installation. The person who installs the product must specify that it is being installed for all users. Also, the person who installs the product must specify that the system PATH should be changed.)

πŸ“– Read

via "National Vulnerability Database".
πŸ” Configuration Essential to MFA Enforcement πŸ”

Organizations should enforce MFA for all users but avoid default MFA protocols that can be abused to steal sensitive data.

πŸ“– Read

via "".
❌ Dev Sabotages Popular NPM Package to Protest Russian Invasion ❌

In the latest software supply-chain attack, the code maintainer added malicious code to the hugely popular node-ipc library to replace files with a heart emoji and a peacenotwar module.

πŸ“– Read

via "Threat Post".
πŸ•΄ Titaniam Announces Completion of Product Suite πŸ•΄

The Titaniam Suite includes ransomware and extortion defense capabilities in the form of five products.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cloudflare Announces API Gateway πŸ•΄

Organizations can secure, manage, and monitor all of their APIs in one easy-to-use dashboard.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Glasswall Launches Freemium Version of its Desktop Content Disarm and Reconstruction App πŸ•΄

Glasswall technology offers proactive protection from file-based cybersecurity threats.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Nok Nok Labs Unveils S3 Authentication Suite πŸ•΄

Enhancements include support for OpenID Connect as an integration mechanism.

πŸ“– Read

via "Dark Reading".