πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25598 β€Ό

Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23869 β€Ό

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1178 β€Ό

Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1155 β€Ό

Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1154 β€Ό

Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1181 β€Ό

Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24131 β€Ό

DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1180 β€Ό

Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1179 β€Ό

Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Security Complexity Is Being Weaponized πŸ•΄

As environments grow noisier, it becomes easier for attackers to intentionally create distractions.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ β€˜Dangerous’ EU web authentication plan threatens to undercut browser-led certification system, detractors claim πŸ—“οΈ

Signatories to a letter criticizing EU scheme share their misgivings with The Daily Swig

πŸ“– Read

via "The Daily Swig".
⚠ Zlib data compressor fixes 17-year-old security bug – patch, errrm, now ⚠

This code is venerable! Surely all the bugs must be out by now?

πŸ“– Read

via "Naked Security".
πŸ—“οΈ SQL injection protections in ImpressCMS could be bypassed to achieve RCE πŸ—“οΈ

Features designed to protect against SQL injection could be abused and turned against the host application

πŸ“– Read

via "The Daily Swig".
⚠ World Backup Day: 5 data recovery tips for everyone! ⚠

The only backup you will ever regret is the one you didn't make

πŸ“– Read

via "Naked Security".
πŸ”₯1
πŸ•΄ Cloud Security Architecture Needs to Be Strategic, Realistic, and Based on Risk πŸ•΄

Info-Tech Research Group has released a new research blueprint to help organizations plan the components necessary to build a cloud security architecture.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-25619 β€Ό

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯1
β€Ό CVE-2022-25620 β€Ό

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vulnerable server. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯1
❌ Lapsus$ β€˜Back from Vacation’ ❌

Lapsus$ added IT giant Globant plus 70GB of leaked data – including admin credentials for scads of customers' DevOps platforms – to its hit list.

πŸ“– Read

via "Threat Post".
❌ Google Chrome Bug Actively Exploited as Zero-Day ❌

The internet giant issued an update for the bug, which is found in the open-source V8 JavaScript engine.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Spring Cloud framework commits patch for code injection flaw πŸ—“οΈ

A fix appears to have been pushed but is not available in a stable release yet

πŸ“– Read

via "The Daily Swig".
⚠ β€œVMWare Spring Cloud” Java bug gives instant remote code execution – update now! ⚠

Easy unauthenticated remote code execution - PoC code already out

πŸ“– Read

via "Naked Security".
πŸ‘1