πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-20741 β€Ό

A vulnerability in the web-based management interface of the Network Diagrams application for Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

πŸ“– Read

via "National Vulnerability Database".
πŸ” U.S. Disrupts Russian Botnet πŸ”

The Cyclops Blink botnet, which the U.S. has removed from vulnerable internet-connected firewall devices, been linked to the Russian hacking group Sandworm.

πŸ“– Read

via "".
πŸ•΄ Eliminating Passwords: One Way Forward πŸ•΄

Fast Identity Online (FIDO) technology leverages security keys and biometrics to provide secure authentication.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Nearly 40% of Macs Left Exposed to Two Zero-Day Exploits πŸ•΄

Apple's emergency fixes last week for two actively exploited vulnerabilities neglected previous Big Sur and Catalina versions of macOS, security vendor says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-26607 β€Ό

A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26591 β€Ό

FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26613 β€Ό

PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26605 β€Ό

eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Zoom's Bug Bounty Programs Soar to $1.8M πŸ•΄

Like other software-reliant firms, the company raised its rewards to spur additional scrutiny by security researchers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Nearly Two-Thirds of Ransomware Victims Paid Ransoms Last Year, Finds "2022 Cyberthreat Defense Report" πŸ•΄

Record-setting ransomware attacks, a shortage of skilled personnel, and low security awareness across the workforce cause headaches for IT security teams.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-22253 β€Ό

Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitrary Telnet connections with the victim device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27374 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27819 β€Ό

SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such as a block or character device).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27376 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27373 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27375 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27818 β€Ό

SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.

πŸ“– Read

via "National Vulnerability Database".
⚠ Serious Security: Darkweb drugs market Hydra taken offline by German police ⚠

Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...

πŸ“– Read

via "Naked Security".
❀1πŸ‘1
⚠ S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast] ⚠

Latest episode - listen now! Cybersecurity news and advice in plain English.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-46416 β€Ό

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23900 β€Ό

A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.

πŸ“– Read

via "National Vulnerability Database".