πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25266 β€Ό

Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20093 β€Ό

The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27192 β€Ό

The Reporting module in Aseco Lietuva document management system DVS Avilys before 2022-03-10 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0315 β€Ό

Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Flash loan attack on One Ring protocol nets crypto-thief $1.4 million πŸ—“οΈ

Price manipulation of LP tokens ejected OShare tokens from protocol

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0145 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1061 β€Ό

Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

πŸ“– Read

via "National Vulnerability Database".
❌ Top 3 Attack Trends in API Security – Podcast ❌

Bots & automated attacks have exploded, with attackers and developers alike in love with APIs, according to a new Cequence Security report. Hacker-in-residence Jason Kent explains the latest.

πŸ“– Read

via "Threat Post".
❌ Microsoft Help Files Disguise Vidar Malware ❌

Attackers are hiding interesting malware in a boring place, hoping victims won’t bother to look.

πŸ“– Read

via "Threat Post".
❌ Tax-Season Scammers Spoof Fintechs, Including Stash, Public ❌

Threat actors are impersonating such wildly popular personal-finance apps (which are used more than social media or streaming services) to try to fool people into giving up their credentials.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ FBI Most Wanted Russian national accused of running dark web marketplace πŸ—“οΈ

The 23-year-old has been indicted for operating a successful carding ring

πŸ“– Read

via "The Daily Swig".
⚠ S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ•΄ What the Conti Ransomware Group Data Leak Tells Us πŸ•΄

Knowing the inner workings of Conti will not only help ransomware negotiators but also help organizations to better handle a ransomware attack when it happens.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-43700 β€Ό

An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1052 β€Ό

Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.

πŸ“– Read

via "National Vulnerability Database".
❌ Chinese APT Combines Fresh Hodur RAT with Complex Anti-Detection ❌

Mustang Panda's already sophisticated cyberespionage campaign has matured even further with the introduction of a brand-new PlugX RAT variant.

πŸ“– Read

via "Threat Post".
πŸ›  Wireshark Analyzer 3.6.3 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
πŸ—“οΈ Microweber developers resolve XSS vulnerability in CMS software πŸ—“οΈ

Content filtering shortcomings led to web security flaw

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0551 β€Ό

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43659 β€Ό

In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0955 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4.

πŸ“– Read

via "National Vulnerability Database".