πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Automaker Cybersecurity Lagging Behind Tech Adoption, Experts Warn ❌

A bug in Honda is indicative of the sprawling car-attack surface that could give cyberattackers easy access to victims, as global use of β€˜smart car tech’ and EVs surges.

πŸ“– Read

via "Threat Post".
πŸ” U.S. Election Officials Targeted in Phishing Campaign πŸ”

The campaign is part of what the FBI calls "a concerted effort to target US election officials."

πŸ“– Read

via "".
⚠ Two different β€œVMware Spring” bugs at large – we cut through the confusion ⚠

Whoever came up with the name "Spring4Shell" didn't help at all... we cut through the Spring Bug confusion

πŸ“– Read

via "Naked Security".
❌ Belarusian β€˜Ghostwriter’ Actor Picks Up BitB for Ukraine-Related Attacks ❌

Ghostwriter is one of 3 campaigns using war-themed attacks, with cyber-fire coming in from government-backed actors in China, Iran, North Korea & Russia.

πŸ“– Read

via "Threat Post".
πŸ•΄ U.S. Cyber Command Adds APUS as Member in Newly Formed Academic Network πŸ•΄

The Academic Engagement Network is designed to advance cybersecurity in four areas.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-34257 β€Ό

Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0350 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43506 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43505 β€Ό

Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43484 β€Ό

A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42869 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43478 β€Ό

A vulnerability exists in Hoosk 1.8.0 in /install/index.php, due to a failure to check if config.php already exists in the root directory, which could let a malicious user reinstall the website.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42868 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42866 β€Ό

A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22311 β€Ό

IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42867 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36625 β€Ό

An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42946 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37517 β€Ό

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Global BEC Crackdown Nets 65 Suspects πŸ•΄

FBI and international law enforcement agencies execute "Operation Eagle Sweep."

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ransomware: Should Companies Ever Pay Up? πŸ•΄

Ransomware is a major threat, and no business is "too small to target." So what should you do after an attack? Is negotiating with criminals ever the answer?

πŸ“– Read

via "Dark Reading".