πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-0551 β€Ό

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43659 β€Ό

In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0955 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1058 β€Ό

Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39491 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0550 β€Ό

Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ APIs & the Software Supply Chain β€” Evolving Security for Today's Digital Ecosystem πŸ•΄

Securing APIs requires both a "shift left" methodology and "shield right" action.

πŸ“– Read

via "Dark Reading".
❌ HubSpot Data Breach Ripples Through Crytocurrency Industry ❌

~30 crypto companies were affected, including BlockFi, Swan Bitcoin and NYDIG, providing an uncomfortable reminder about how much data CRM systems snarf up.

πŸ“– Read

via "Threat Post".
πŸ•΄ For MSPs, Next-Gen Email Security Is a Must πŸ•΄

Stay one step ahead of the constantly evolving cyber threats with the right MSP email security solution. Discover how to evaluate and select the best service and solutions for your clients.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-21820 β€Ό

NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data confidentiality and integrity.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26629 β€Ό

An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0153 β€Ό

SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25568 β€Ό

MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Casinos Can Prevent Loyalty Incentive and Account Takeover Fraud πŸ•΄

As casinos go digital, their loyalty programs and authentic accounts are at risk.

πŸ“– Read

via "Dark Reading".
❌ Just-Released Dark Souls Game, Elden Ring, Includes Killer Bug ❌

A patch fixes exploit hidden in Elden Ring that traps PC players in a β€˜death loop.’

πŸ“– Read

via "Threat Post".
πŸ” Proposed Commission Would Seek to Modernize HIPAA πŸ”

As part of new legislation, a new commission would assess the current state of health data privacy and lay the groundwork for modernizing HIPAA.

πŸ“– Read

via "".
β€Ό CVE-2021-43085 β€Ό

An Insecure Permissions vulnerability exists in the OpenSSL Project 3.0 due to an error in the implementation of the CMAC_Final() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43666 β€Ό

A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22374 β€Ό

The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to downgrade attack which may affect its ability to operate its host. IBM X-Force ID: 221442.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43084 β€Ό

An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft Azure Developers Awash in PII-Stealing npm Packages ❌

A large-scale, automated typosquatting attack saw 200+ malicious packages flood the npm code repository, targeting popular Azure scopes.

πŸ“– Read

via "Threat Post".