βΌ CVE-2021-44226 βΌ
π Read
via "National Vulnerability Database".
Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22819 βΌ
π Read
via "National Vulnerability Database".
NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code execution via a crafted unsigned update.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25267 βΌ
π Read
via "National Vulnerability Database".
Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).π Read
via "National Vulnerability Database".
βΌ CVE-2022-25041 βΌ
π Read
via "National Vulnerability Database".
OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.π Read
via "National Vulnerability Database".
βΌ CVE-2020-20094 βΌ
π Read
via "National Vulnerability Database".
Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messagesπ Read
via "National Vulnerability Database".
βΌ CVE-2020-20096 βΌ
π Read
via "National Vulnerability Database".
Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27254 βΌ
π Read
via "National Vulnerability Database".
The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25268 βΌ
π Read
via "National Vulnerability Database".
Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25266 βΌ
π Read
via "National Vulnerability Database".
Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).π Read
via "National Vulnerability Database".
βΌ CVE-2020-20093 βΌ
π Read
via "National Vulnerability Database".
The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27192 βΌ
π Read
via "National Vulnerability Database".
The Reporting module in Aseco Lietuva document management system DVS Avilys before 2022-03-10 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0315 βΌ
π Read
via "National Vulnerability Database".
Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.π Read
via "National Vulnerability Database".
ποΈ Flash loan attack on One Ring protocol nets crypto-thief $1.4 million ποΈ
π Read
via "The Daily Swig".
Price manipulation of LP tokens ejected OShare tokens from protocolπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Flash loan attack on One Ring protocol nets crypto-thief $1.4 million
Price manipulation of LP tokens ejected OShare tokens from protocol
βΌ CVE-2022-0145 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1061 βΌ
π Read
via "National Vulnerability Database".
Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.π Read
via "National Vulnerability Database".
β Top 3 Attack Trends in API Security β Podcast β
π Read
via "Threat Post".
Bots & automated attacks have exploded, with attackers and developers alike in love with APIs, according to a new Cequence Security report. Hacker-in-residence Jason Kent explains the latest.π Read
via "Threat Post".
Threat Post
Top 3 Attack Trends in API Security β Podcast
Bots & automated attacks have exploded, with attackers and developers alike in love with APIs, according to a new Cequence Security report. Hacker-in-residence Jason Kent explains the latest.
β Microsoft Help Files Disguise Vidar Malware β
π Read
via "Threat Post".
Attackers are hiding interesting malware in a boring place, hoping victims wonβt bother to look.π Read
via "Threat Post".
Threat Post
Microsoft Help Files Disguise Vidar Malware
Attackers are hiding interesting malware in a boring place, hoping victims wonβt bother to look.
β Tax-Season Scammers Spoof Fintechs, Including Stash, Public β
π Read
via "Threat Post".
Threat actors are impersonating such wildly popular personal-finance apps (which are used more than social media or streaming services) to try to fool people into giving up their credentials.π Read
via "Threat Post".
Threat Post
Tax-Season Scammers Spoof Fintechs, Including Stash, Public
Threat actors are impersonating such wildly popular personal-finance apps (which are used more than social media or streaming services) to try to fool people into giving up their credentials.
ποΈ FBI Most Wanted Russian national accused of running dark web marketplace ποΈ
π Read
via "The Daily Swig".
The 23-year-old has been indicted for operating a successful carding ringπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
FBI Most Wanted Russian national accused of running dark web marketplace
The 23-year-old has been indicted for operating a successful carding ring
β S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast] β
π Read
via "Naked Security".
Latest episode - listen now!π Read
via "Naked Security".
Naked Security
S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]
Latest episode β listen now!
π΄ What the Conti Ransomware Group Data Leak Tells Us π΄
π Read
via "Dark Reading".
Knowing the inner workings of Conti will not only help ransomware negotiators but also help organizations to better handle a ransomware attack when it happens.π Read
via "Dark Reading".
Dark Reading
What the Conti Ransomware Group Data Leak Tells Us
Knowing the inner workings of Conti will not only help ransomware negotiators but also help organizations to better handle a ransomware attack when it happens.