πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ World Backup Day: 5 data recovery tips for everyone! ⚠

The only backup you will ever regret is the one you didn't make

πŸ“– Read

via "Naked Security".
πŸ”₯1
πŸ•΄ Cloud Security Architecture Needs to Be Strategic, Realistic, and Based on Risk πŸ•΄

Info-Tech Research Group has released a new research blueprint to help organizations plan the components necessary to build a cloud security architecture.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-25619 β€Ό

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯1
β€Ό CVE-2022-25620 β€Ό

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vulnerable server. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯1
❌ Lapsus$ β€˜Back from Vacation’ ❌

Lapsus$ added IT giant Globant plus 70GB of leaked data – including admin credentials for scads of customers' DevOps platforms – to its hit list.

πŸ“– Read

via "Threat Post".
❌ Google Chrome Bug Actively Exploited as Zero-Day ❌

The internet giant issued an update for the bug, which is found in the open-source V8 JavaScript engine.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Spring Cloud framework commits patch for code injection flaw πŸ—“οΈ

A fix appears to have been pushed but is not available in a stable release yet

πŸ“– Read

via "The Daily Swig".
⚠ β€œVMWare Spring Cloud” Java bug gives instant remote code execution – update now! ⚠

Easy unauthenticated remote code execution - PoC code already out

πŸ“– Read

via "Naked Security".
πŸ‘1
πŸ•΄ Cybercriminals Fighting Over Cloud Workloads for Cryptomining πŸ•΄

Whether compromising misconfigured cloud infrastructure or taking advantage of free-tier cloud development platforms, attackers see a vast pool of workloads to use for cryptomining.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Smart Cities: Secure by Design? It Takes a Village πŸ•΄

Smart-city security breaches have potentially very serious consequences β€” they can be economically devastating and even life-threatening, if handled wrong.

πŸ“– Read

via "Dark Reading".
❌ Cyberattackers Target UPS Backup Power Devices in Mission-Critical Environments ❌

The active attacks could result in critical-infrastructure damage, business disruption, lateral movement and more.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-39751 β€Ό

In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-172838801

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39758 β€Ό

In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-205130886

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39755 β€Ό

In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-204995407

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39784 β€Ό

In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-200163477

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39739 β€Ό

In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-184525194

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39742 β€Ό

In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-186405602

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39779 β€Ό

In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call state with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-190400974

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20002 β€Ό

In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-198657657

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39776 β€Ό

In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-192614125

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44312 β€Ό

An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a crafted web page.

πŸ“– Read

via "National Vulnerability Database".