πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-30328 β€Ό

Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30332 β€Ό

Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

πŸ“– Read

via "National Vulnerability Database".
πŸ‘2
β€Ό CVE-2021-30333 β€Ό

Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ PHP bug allows attackers to bypass domain filters, stage DoS attacks against servers πŸ—“οΈ

Filter bypass flaw is triggered only on very large user input, which puts restrictions on its exploitability

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-46443 β€Ό

Spoofer 1.4.6 suffers from unquoted service paths vulnerability. An attacker as a low privileged local user can hijack the execution flow of the application to escalate privileges by inserting a malicious executable in a higher level directory with the vulnerable path.

πŸ“– Read

via "National Vulnerability Database".
❌ Apple Rushes Out Patches for 0-Days in MacOS, iOS ❌

The vulnerabilities could allow threat actors to disrupt or access kernel activity and may be under active exploit.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ GitLab addresses critical account hijack bug πŸ—“οΈ

Monthly release also addresses pair of stored XSS flaws

πŸ“– Read

via "The Daily Swig".
πŸ‘1
πŸ•΄ More Than Ever, Security Matters πŸ•΄

Public policy proposals must consider technical, practical, and real-world security effects, and make sure we avoid unintended consequences.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24181 β€Ό

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Bug Bounty Radar // The latest bug bounty programs for April 2022 πŸ—“οΈ

New web targets for the discerning hacker

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-44135 β€Ό

pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 4/1 πŸ”

Hacked satellites, how technology enables data protection, and the fastest ransomware - catch up on the infosec news of the week with the Friday Five!

πŸ“– Read

via "".
πŸ•΄ What You Need to Know About PCI DSS 4.0's New Requirements πŸ•΄

The goal for PCI DSS v4.0 is to β€œaddress emerging threats and technologies and enable innovative methods to combat new threats” to customer payment information, the PCI Security Standards Council says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-22404 β€Ό

IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulnerable to denial of service due to excessive rate limiting.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22332 β€Ό

IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21235 β€Ό

The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22328 β€Ό

IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another users data. IBM X-Force ID: 218871.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22331 β€Ό

IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22327 β€Ό

IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 218859.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ NSA Employee Indicted for Sending Classified Data Outside the Agency πŸ•΄

Even the NSA has a malicious insider problem. The employee used his personal emails to send classified data to unauthorized outsiders on 13 different occasions.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-21223 β€Ό

The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

πŸ“– Read

via "National Vulnerability Database".