πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-27950 β€Ό

In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.

πŸ“– Read

via "National Vulnerability Database".
⚠ UK police arrest 7 hacking suspects – have they bust the LAPSUS$ gang? ⚠

Seven alleged hackers have been arrested in the UK. But who are they, and which hacking crew are they from?

πŸ“– Read

via "Naked Security".
πŸ—“οΈ FCC adds Kaspersky products to list of national security threats as Russian invasion of Ukraine continues πŸ—“οΈ

Russian antivirus vendor cited in expanded guidance

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Security's Life Cycle Isn't the Developers' Life Cycle πŸ•΄

Whether it's PCI-DSS, SSDLC, or GDPR, the criteria that security standards expect businesses to uphold are neither realistic or feasible.

πŸ“– Read

via "Dark Reading".
⚠ Google Chrome patches mysterious new zero-day bug – update now ⚠

CVE-2022-1096 - another mystery in-the-wild 0-day in Chrome... check your version now!

πŸ“– Read

via "Naked Security".
πŸ‘1
β€Ό CVE-2022-23884 β€Ό

Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23882 β€Ό

TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46434 β€Ό

** UNSUPPORTED WHEN ASSIGNED ** EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the application returns different results depending on whether the account is correct, that allowed an attacker to determine if a given username was valid.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43725 β€Ό

There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0342 β€Ό

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ ENISA urges data-handling innovation amid growing tide of healthcare breaches πŸ—“οΈ

Infosec agency sets out use cases for clinical trials, data exchange, and connected devices

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Attackers getting faster at latching onto unpatched vulnerabilities for stealth hacking campaigns – report πŸ—“οΈ

Enterprises need to be ready with β€˜battle-tested incident response procedures’ as zero-day exploitation ramps up

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-43721 β€Ό

Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();>

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44103 β€Ό

Vertical Privilege Escalation in KONGA 0.14.9 allows attackers to higher privilege users to full administration access. The attack vector is a crafted condition, as demonstrated by the /api/user/{ID} at ADMIN parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical Sophos Security Bug Allows RCE on Firewalls ❌

The security vendor's appliance suffers from an authentication-bypass issue.

πŸ“– Read

via "Threat Post".
❀1
β€Ό CVE-2021-44124 β€Ό

Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker can navigate through the device's File System over HTTP.

πŸ“– Read

via "National Vulnerability Database".
❌ Okta Says It Goofed in Handling the Lapsus$ Attack ❌

"We made a mistake," Okta said, owning up to its responsibility for security incidents that hit its service providers and potentially its own customers.

πŸ“– Read

via "Threat Post".
πŸ•΄ Vodafone Portugal: The Attack on Brand Reputations and Public Confidence Through Cybercrime πŸ•΄

Companies must prepare effective, data-driven threat-response strategies as they monitor for reputational risks as well as cyberattacks.

πŸ“– Read

via "Dark Reading".
πŸ” Google: Update Chrome Now to Fix Zero-Day πŸ”

An emergency update for Google Chrome, released Friday, fixes a zero-day that's being exploited in attacks.

πŸ“– Read

via "".
β€Ό CVE-2022-1056 β€Ό

Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26980 β€Ό

Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.

πŸ“– Read

via "National Vulnerability Database".