π΄ Nearly 40% of Macs Left Exposed to Two Zero-Day Exploits π΄
π Read
via "Dark Reading".
Apple's emergency fixes last week for two actively exploited vulnerabilities neglected previous Big Sur and Catalina versions of macOS, security vendor says.π Read
via "Dark Reading".
Dark Reading
Nearly 40% of Macs Left Exposed to 2 Zero-Day Exploits
Apple's emergency fixes last week for two actively exploited vulnerabilities neglected previous Big Sur and Catalina versions of macOS, security vendor says.
βΌ CVE-2022-26607 βΌ
π Read
via "National Vulnerability Database".
A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26591 βΌ
π Read
via "National Vulnerability Database".
FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26613 βΌ
π Read
via "National Vulnerability Database".
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26605 βΌ
π Read
via "National Vulnerability Database".
eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.π Read
via "National Vulnerability Database".
π΄ Zoom's Bug Bounty Programs Soar to $1.8M π΄
π Read
via "Dark Reading".
Like other software-reliant firms, the company raised its rewards to spur additional scrutiny by security researchers.π Read
via "Dark Reading".
Dark Reading
Zoom's Bug Bounty Programs Soar to $1.8M
Like other software-reliant firms, the company raised its rewards to spur additional scrutiny by security researchers.
π΄ Nearly Two-Thirds of Ransomware Victims Paid Ransoms Last Year, Finds "2022 Cyberthreat Defense Report" π΄
π Read
via "Dark Reading".
Record-setting ransomware attacks, a shortage of skilled personnel, and low security awareness across the workforce cause headaches for IT security teams.π Read
via "Dark Reading".
Dark Reading
Nearly Two-Thirds of Ransomware Victims Paid Ransoms Last Year, Finds "2022 Cyberthreat Defense Report"
Record-setting ransomware attacks, a shortage of skilled personnel, and low security awareness across the workforce cause headaches for IT security teams.
βΌ CVE-2020-22253 βΌ
π Read
via "National Vulnerability Database".
Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitrary Telnet connections with the victim device.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27374 βΌ
π Read
via "National Vulnerability Database".
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27819 βΌ
π Read
via "National Vulnerability Database".
SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such as a block or character device).π Read
via "National Vulnerability Database".
βΌ CVE-2020-27376 βΌ
π Read
via "National Vulnerability Database".
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27373 βΌ
π Read
via "National Vulnerability Database".
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27375 βΌ
π Read
via "National Vulnerability Database".
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27818 βΌ
π Read
via "National Vulnerability Database".
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.π Read
via "National Vulnerability Database".
β Serious Security: Darkweb drugs market Hydra taken offline by German police β
π Read
via "Naked Security".
Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...π Read
via "Naked Security".
Naked Security
Serious Security: Darkweb drugs market Hydra taken offline by German police
Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain Englishβ¦
β€1π1
β S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast] β
π Read
via "Naked Security".
Latest episode - listen now! Cybersecurity news and advice in plain English.π Read
via "Naked Security".
Naked Security
S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast]
Latest episode β listen now! Cybersecurity news and advice in plain English.
βΌ CVE-2021-46416 βΌ
π Read
via "National Vulnerability Database".
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23900 βΌ
π Read
via "National Vulnerability Database".
A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46417 βΌ
π Read
via "National Vulnerability Database".
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.π Read
via "National Vulnerability Database".
π1
β MacOS Malware: Myth vs. Truth β Podcast β
π Read
via "Threat Post".
Huntress Labs R&D Director Jamie Levy busts the old βMacs donβt get virusesβ myth and offers tips on how MacOS malware differs and how to protect against it.π Read
via "Threat Post".
ποΈ Apple paid out $36,000 bug bounty for HTTP request smuggling flaws on core web apps β research ποΈ
π Read
via "The Daily Swig".
Queue poisoning attacks allegedly put accounts at risk of takeoverπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Apple paid out $36,000 bug bounty for HTTP request smuggling flaws on core web apps β research
Queue poisoning attacks allegedly put accounts at risk of takeover