πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-43735 β€Ό

CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23242 β€Ό

TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of a process crash. Knowledge of the crash event and the TeamViewer ID as well as either possession of the pre-crash connection password or local authenticated access to the machine would have allowed to establish a remote connection by reusing the not properly deleted connection password.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Cybercrime Cost U.S. $6.9 Billion in 2021 πŸ”

The FBI's annual look at phishing, scam, and personal data breach statistics is out.

πŸ“– Read

via "".
πŸ•΄ Okta Says 366 Customers Impacted via Third-Party Breach πŸ•΄

Microsoft meanwhile confirms Lapsus$ group compromised it as well and issues warning on threat actor.

πŸ“– Read

via "Dark Reading".
πŸ•΄ FBI: Cybercrime Victims Suffered Losses of Over $6.9B in 2021 πŸ•΄

The Internet Crime Complaint Center fielded 847,376 cybercrime reports last year, an increase of 7% from 2020.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-38278 β€Ό

Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46064 β€Ό

IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26243 β€Ό

Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38772 β€Ό

Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ A Closer Look at the LAPSUS$ Data Extortion Group β™ŸοΈ

Microsoft and identity management platform Okta both disclosed this week breaches involving LAPSUS$, a relatively new cybercrime group that specializes in stealing data from big companies and threatening to publish the information unless a ransom demand is paid. Here's a closer look at LAPSUS$, and some of the low-tech but high-impact methods the group uses to gain access to targeted organizations.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2021-3748 β€Ό

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25223 β€Ό

Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=transaction/view_details' via the 'id' parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23881 β€Ό

ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27466 β€Ό

A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24292 β€Ό

Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24757 β€Ό

The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter Server logs by default. Considering these logs do not require root access, an attacker can monitor these logs, steal sensitive auth/cookie information, and gain access to the Jupyter server. Jupyter Server version 1.15.4 contains a patch for this issue. There are currently no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1030 β€Ό

Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22951 β€Ό

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25222 β€Ό

Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22952 β€Ό

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23880 β€Ό

An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".