πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25348 β€Ό

Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25915 β€Ό

Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attacker to bypass access restriction and to access the management screen of the product via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ US healthcare data breach impacts 85,000 law enforcement officers πŸ—“οΈ

Law Enforcement Health Benefits was hit by a ransomware attack last year

πŸ“– Read

via "The Daily Swig".
πŸ‘2
β€Ό CVE-2022-24136 β€Ό

Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1176 β€Ό

Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Critical SQL injection flaw fixed in Rapid7’s Nexpose vulnerability scanner πŸ—“οΈ

Attacks could be mounted via manipulation of query operators in search criteria

πŸ“– Read

via "The Daily Swig".
❌ A Blockchain Primer and a Bored Ape Headscratcher – Podcast ❌

Mystified? Now’s the time to learn about cryptocurrency-associated risks: Listen to KnowBe4’s Dr. Lydia Kostopoulos explain blockchain, NFTs and how to stay safe.

πŸ“– Read

via "Threat Post".
πŸ•΄ Nation-State Hackers Ramp Up Ukraine War-Themed Attacks πŸ•΄

Among them is the operator of the Ghostwriter misinformation campaign, with a new browser-in-browser phishing technique, according to Google's research team.

πŸ“– Read

via "Dark Reading".
❌ QNAP Customers Adrift, Waiting on Fix for OpenSSL Bug ❌

QNAP is warning clients that a recently disclosed vulnerability affects most of its NAS devices, with no mitigation available while the vendor readies a patch.

πŸ“– Read

via "Threat Post".
⚠ World Backup Day: 5 data recovery tips for everyone! ⚠

The only backup you will ever regret is the one you didn't make

πŸ“– Read

via "Naked Security".
πŸ‘1
⚠ S3 Ep76: Deadbolt, LAPSUS$, Zlib, and a Chrome 0-day [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
⚠ β€œVMware Spring Cloud” Java bug gives instant remote code execution – update now! ⚠

Easy unauthenticated remote code execution - PoC code already out

πŸ“– Read

via "Naked Security".
πŸ•΄ Protecting Your Organization Against a New Class of Cyber Threats: HEAT πŸ•΄

Take a preventative threat approach and apply security measures near end users, applications, and data to increase protection.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Spring4Shell: Spring users face new, zero-day vulnerability πŸ—“οΈ

Both security bugs are now reportedly being exploited in the wild

πŸ“– Read

via "The Daily Swig".
❌ Automaker Cybersecurity Lagging Behind Tech Adoption, Experts Warn ❌

A bug in Honda is indicative of the sprawling car-attack surface that could give cyberattackers easy access to victims, as global use of β€˜smart car tech’ and EVs surges.

πŸ“– Read

via "Threat Post".
πŸ” U.S. Election Officials Targeted in Phishing Campaign πŸ”

The campaign is part of what the FBI calls "a concerted effort to target US election officials."

πŸ“– Read

via "".
⚠ Two different β€œVMware Spring” bugs at large – we cut through the confusion ⚠

Whoever came up with the name "Spring4Shell" didn't help at all... we cut through the Spring Bug confusion

πŸ“– Read

via "Naked Security".
❌ Belarusian β€˜Ghostwriter’ Actor Picks Up BitB for Ukraine-Related Attacks ❌

Ghostwriter is one of 3 campaigns using war-themed attacks, with cyber-fire coming in from government-backed actors in China, Iran, North Korea & Russia.

πŸ“– Read

via "Threat Post".
πŸ•΄ U.S. Cyber Command Adds APUS as Member in Newly Formed Academic Network πŸ•΄

The Academic Engagement Network is designed to advance cybersecurity in four areas.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-34257 β€Ό

Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0350 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

πŸ“– Read

via "National Vulnerability Database".