πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-26249 β€Ό

Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26301 β€Ό

TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26272 β€Ό

A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file application/config/config.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25575 β€Ό

Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via crafted payloads injected into the user name, password, and verification code text boxes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25576 β€Ό

Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts.

πŸ“– Read

via "National Vulnerability Database".
⚠ UK police arrest 7 hacking suspects – have they bust the LAPSUS$ gang? ⚠

Seven alleged hackers have been arrested in the UK. But who are they, and which hacking crew are they from?

πŸ“– Read

via "Naked Security".
πŸ‘2
β€Ό CVE-2018-25032 β€Ό

zlib 1.2.11 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22687 β€Ό

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22688 β€Ό

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ HTTP request smuggling bug patched in mitmproxy πŸ—“οΈ

Bug exploited inconsistencies between intermediary and backend servers

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-44751 β€Ό

A vulnerability affecting F-Secure SAFE browser before March 22, 2022 was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F-Secure browser which can be exploited by an attacker to send unwanted USSD messages or perform unwanted calls. In most modern Android OS, dialer application will require user interaction, however, some older Android OS may not need user interaction.

πŸ“– Read

via "National Vulnerability Database".
❌ Google Chrome Zero-Day Bugs Exploited Weeks Ahead of Patch ❌

Two separate campaigns from different threat actors targeted users with the same exploit kit for more than a month before the company fixed an RCE flaw found in February.

πŸ“– Read

via "Threat Post".
πŸ•΄ HR Alone Can't Solve the Great Resignation πŸ•΄

Here's how IT teams and decision-makers can step up to support the workforce. Creating a culture of feedback and introducing automation can mitigate burnout, inspire employees, and reduce turnover.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1064 β€Ό

SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1040 β€Ό

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Four Russian government employees charged over hacking campaigns on critical infrastructure πŸ—“οΈ

Historical crimes unsealed by US courts

πŸ“– Read

via "The Daily Swig".
πŸ‘1
πŸ—“οΈ Washington residents’ medical data exposed by phishing attack on Spokane Regional Health District πŸ—“οΈ

Medications and test results among data potentially β€˜previewed’ by attacker

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-27227 β€Ό

In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Estonian Tied to 13 Ransomware Attacks Gets 66 Months in Prison β™ŸοΈ

An Estonian man was sentenced today to more than five years in a U.S. prison for his role in at least 13 ransomware attacks that caused losses of approximately $53 million. Prosecutors say the accused also enjoyed a lengthy career of "cashing out" access to hacked bank accounts worldwide.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Here's How Fast Ransomware Encrypts Files πŸ•΄

New analysis shows how long it takes for each of the top 10 ransomware families to encrypt 100,000 files.

πŸ“– Read

via "Dark Reading".
πŸ•΄ WiCyS Members Now Have access to Cyber Defense Challenge Through Target πŸ•΄

Target's cybersecurity team has designed a Cyber Defense Challenge exclusively for members of Women in CyberSecurity (WiCyS).

πŸ“– Read

via "Dark Reading".