πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1176 β€Ό

Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Critical SQL injection flaw fixed in Rapid7’s Nexpose vulnerability scanner πŸ—“οΈ

Attacks could be mounted via manipulation of query operators in search criteria

πŸ“– Read

via "The Daily Swig".
❌ A Blockchain Primer and a Bored Ape Headscratcher – Podcast ❌

Mystified? Now’s the time to learn about cryptocurrency-associated risks: Listen to KnowBe4’s Dr. Lydia Kostopoulos explain blockchain, NFTs and how to stay safe.

πŸ“– Read

via "Threat Post".
πŸ•΄ Nation-State Hackers Ramp Up Ukraine War-Themed Attacks πŸ•΄

Among them is the operator of the Ghostwriter misinformation campaign, with a new browser-in-browser phishing technique, according to Google's research team.

πŸ“– Read

via "Dark Reading".
❌ QNAP Customers Adrift, Waiting on Fix for OpenSSL Bug ❌

QNAP is warning clients that a recently disclosed vulnerability affects most of its NAS devices, with no mitigation available while the vendor readies a patch.

πŸ“– Read

via "Threat Post".
⚠ World Backup Day: 5 data recovery tips for everyone! ⚠

The only backup you will ever regret is the one you didn't make

πŸ“– Read

via "Naked Security".
πŸ‘1
⚠ S3 Ep76: Deadbolt, LAPSUS$, Zlib, and a Chrome 0-day [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
⚠ β€œVMware Spring Cloud” Java bug gives instant remote code execution – update now! ⚠

Easy unauthenticated remote code execution - PoC code already out

πŸ“– Read

via "Naked Security".
πŸ•΄ Protecting Your Organization Against a New Class of Cyber Threats: HEAT πŸ•΄

Take a preventative threat approach and apply security measures near end users, applications, and data to increase protection.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Spring4Shell: Spring users face new, zero-day vulnerability πŸ—“οΈ

Both security bugs are now reportedly being exploited in the wild

πŸ“– Read

via "The Daily Swig".
❌ Automaker Cybersecurity Lagging Behind Tech Adoption, Experts Warn ❌

A bug in Honda is indicative of the sprawling car-attack surface that could give cyberattackers easy access to victims, as global use of β€˜smart car tech’ and EVs surges.

πŸ“– Read

via "Threat Post".
πŸ” U.S. Election Officials Targeted in Phishing Campaign πŸ”

The campaign is part of what the FBI calls "a concerted effort to target US election officials."

πŸ“– Read

via "".
⚠ Two different β€œVMware Spring” bugs at large – we cut through the confusion ⚠

Whoever came up with the name "Spring4Shell" didn't help at all... we cut through the Spring Bug confusion

πŸ“– Read

via "Naked Security".
❌ Belarusian β€˜Ghostwriter’ Actor Picks Up BitB for Ukraine-Related Attacks ❌

Ghostwriter is one of 3 campaigns using war-themed attacks, with cyber-fire coming in from government-backed actors in China, Iran, North Korea & Russia.

πŸ“– Read

via "Threat Post".
πŸ•΄ U.S. Cyber Command Adds APUS as Member in Newly Formed Academic Network πŸ•΄

The Academic Engagement Network is designed to advance cybersecurity in four areas.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-34257 β€Ό

Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0350 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43506 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43505 β€Ό

Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43484 β€Ό

A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42869 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages.

πŸ“– Read

via "National Vulnerability Database".