πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Ransomware Attack Led Bridgestone to Halt US Tire Production for a Week πŸ•΄

Japanese manufacturer confirmed a Feb. 27 attack on its US subsidiary that led to a temporary production shutdown.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1035 β€Ό

Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25570 β€Ό

In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.

πŸ“– Read

via "National Vulnerability Database".
❌ Bridgestone Hit as Ransomware Torches Toyota Supply Chain ❌

A ransomware attack struck Bridgestone Americas, weeks after another Toyota supplier experienced the same and a third reported some kind of cyber hit.

πŸ“– Read

via "Threat Post".
⚠ OpenSSL patches infinite-loop DoS bug in certificate verification ⚠

When it comes to writing loops in your code... never sit on the fence!

πŸ“– Read

via "Naked Security".
πŸ‘1
β€Ό CVE-2020-24772 β€Ό

In Dreamacro 1.1.0, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like responder) for code execution (or captured for hash cracking).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26494 β€Ό

An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worker name before a Generate CSR request. Only an administrator can update a worker name.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45117 β€Ό

The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.

πŸ“– Read

via "National Vulnerability Database".
⚠ Web vendor CafePress fined $500,000 for giving cybersecurity a low value ⚠

Just because you're the victim of a cybercrime doesn't let you off your cybersecurity obligations

πŸ“– Read

via "Naked Security".
πŸ—“οΈ NPM maintainer targets Russian users with data-wiping β€˜protestware’ πŸ—“οΈ

GUI-rilla warfare

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Name That Toon: Sleep Like a Baby πŸ•΄

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
❌ Conti Ransomware V. 3, Including Decryptor, Leaked ❌

The latest is a fresher version of the ransomware pro-Ukraine researcher ContiLeaks already released, but it’s reportedly clunkier code.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-22394 β€Ό

The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrator or node access to the vulnerable server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26960 β€Ό

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

πŸ“– Read

via "National Vulnerability Database".
πŸ” AvosLocker Ransomware Targeting Critical Infrastructure πŸ”

The ransomware-as-a-service group continues to target critical infrastructure in the U.S.

πŸ“– Read

via "".
❌ Facestealer Trojan Hidden in Google Play Plunders Facebook Accounts ❌

The trojanized Craftsart Cartoon Photo Tools app is available in the official Android app store, but it's actually spyware capable of stealing any and all information from victims' social-media accounts.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-0364 β€Ό

The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0591 β€Ό

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24235 β€Ό

A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0590 β€Ό

The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0687 β€Ό

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

πŸ“– Read

via "National Vulnerability Database".