βΌ CVE-2022-26255 βΌ
π Read
via "National Vulnerability Database".
Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44213 βΌ
π Read
via "National Vulnerability Database".
OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26258 βΌ
π Read
via "National Vulnerability Database".
D-Link DIR-820L 1.05B03 was discovered to contain a remote command execution (RCE) vulnerability via the Device Name parameter in /lan.asp.π Read
via "National Vulnerability Database".
βΌ CVE-2021-45490 βΌ
π Read
via "National Vulnerability Database".
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44211 βΌ
π Read
via "National Vulnerability Database".
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.π Read
via "National Vulnerability Database".
βΌ CVE-2021-26601 βΌ
π Read
via "National Vulnerability Database".
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44210 βΌ
π Read
via "National Vulnerability Database".
OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44209 βΌ
π Read
via "National Vulnerability Database".
OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44212 βΌ
π Read
via "National Vulnerability Database".
OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27950 βΌ
π Read
via "National Vulnerability Database".
In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.π Read
via "National Vulnerability Database".
β UK police arrest 7 hacking suspects β have they bust the LAPSUS$ gang? β
π Read
via "Naked Security".
Seven alleged hackers have been arrested in the UK. But who are they, and which hacking crew are they from?π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
ποΈ FCC adds Kaspersky products to list of national security threats as Russian invasion of Ukraine continues ποΈ
π Read
via "The Daily Swig".
Russian antivirus vendor cited in expanded guidanceπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
FCC adds Kaspersky products to list of national security threats as Russian invasion of Ukraine continues
Russian antivirus vendor cited in expanded guidance
π΄ Security's Life Cycle Isn't the Developers' Life Cycle π΄
π Read
via "Dark Reading".
Whether it's PCI-DSS, SSDLC, or GDPR, the criteria that security standards expect businesses to uphold are neither realistic or feasible.π Read
via "Dark Reading".
Dark Reading
Security's Life Cycle Isn't the Developers' Life Cycle
Whether it's PCI-DSS, SSDLC, or GDPR, the criteria that security standards expect businesses to uphold are neither realistic or feasible.
β Google Chrome patches mysterious new zero-day bug β update now β
π Read
via "Naked Security".
CVE-2022-1096 - another mystery in-the-wild 0-day in Chrome... check your version now!π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π1
βΌ CVE-2022-23884 βΌ
π Read
via "National Vulnerability Database".
Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).π Read
via "National Vulnerability Database".
βΌ CVE-2022-23882 βΌ
π Read
via "National Vulnerability Database".
TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46434 βΌ
π Read
via "National Vulnerability Database".
** UNSUPPORTED WHEN ASSIGNED ** EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the application returns different results depending on whether the account is correct, that allowed an attacker to determine if a given username was valid.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43725 βΌ
π Read
via "National Vulnerability Database".
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0342 βΌ
π Read
via "National Vulnerability Database".
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.π Read
via "National Vulnerability Database".
ποΈ ENISA urges data-handling innovation amid growing tide of healthcare breaches ποΈ
π Read
via "The Daily Swig".
Infosec agency sets out use cases for clinical trials, data exchange, and connected devicesπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
ENISA urges data-handling innovation amid growing tide of healthcare breaches
Infosec agency sets out use cases for clinical trials, data exchange, and connected devices
ποΈ Attackers getting faster at latching onto unpatched vulnerabilities for stealth hacking campaigns β report ποΈ
π Read
via "The Daily Swig".
Enterprises need to be ready with βbattle-tested incident response proceduresβ as zero-day exploitation ramps upπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Attackers getting faster at latching onto unpatched vulnerabilities for stealth hacking campaigns β report
Enterprises need to be ready with βbattle-tested incident response proceduresβ as zero-day exploitation ramps up