πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-26909 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24475, CVE-2022-26891, CVE-2022-26894, CVE-2022-26895, CVE-2022-26900, CVE-2022-26908, CVE-2022-26912.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26895 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24475, CVE-2022-26891, CVE-2022-26894, CVE-2022-26900, CVE-2022-26908, CVE-2022-26909, CVE-2022-26912.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26891 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24475, CVE-2022-26894, CVE-2022-26895, CVE-2022-26900, CVE-2022-26908, CVE-2022-26909, CVE-2022-26912.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26908 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24475, CVE-2022-26891, CVE-2022-26894, CVE-2022-26895, CVE-2022-26900, CVE-2022-26909, CVE-2022-26912.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28116 β€Ό

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28468 β€Ό

Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Developers Increasingly Prioritize Secure Coding πŸ•΄

But "old habits are hard to break," with 48% of developers still shipping code with vulnerabilities.

πŸ“– Read

via "Dark Reading".
⚠ Firefox 99 is out – no major bugs, but update anyway! ⚠

Firefox's four-weekly updates just dropped - here's what you need to know.

πŸ“– Read

via "Naked Security".
⚠ Google’s monthly Android updates patch numerous β€œget root” holes ⚠

Get the update now... if it's available for your phone. Here's how to check.

πŸ“– Read

via "Naked Security".
πŸ•΄ Microsoft Details New Security Features for Windows 11 πŸ•΄

Security features to come include a TPM-like security processor for protecting artifacts that a computer uses during the secure boot-up process, as well as a control for blocking unsigned and untrusted apps.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23446 β€Ό

A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23441 β€Ό

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29013 β€Ό

An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests.

πŸ“– Read

via "National Vulnerability Database".
❌ Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info ❌

Threat actors target Office 365 and Google Workspace in a new campaign, which uses a legitimate domain associated with a road-safety center in Moscow to send messages.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ UK retailer The Works blames store closures on POS problems following cyber-attack πŸ—“οΈ

Discount chain is working to restore stock deliveries

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why XDR As We Know It Will Fail πŸ•΄

Don't take the XDR hype at face value. Do security due diligence and add a connectivity level for data access across all silos for best response.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1253 β€Ό

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1.0.8.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Authorities seize Hydra servers in bust against darknet cybercrime marketplace πŸ—“οΈ

Wretched hive of villainy shut down

πŸ“– Read

via "The Daily Swig".
⚠ Serious Security: Darkweb drugs market Hydra taken offline by German police ⚠

Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-24786 β€Ό

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27108 β€Ό

OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.

πŸ“– Read

via "National Vulnerability Database".