πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-22253 β€Ό

Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitrary Telnet connections with the victim device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27374 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27819 β€Ό

SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such as a block or character device).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27376 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27373 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27375 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27818 β€Ό

SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.

πŸ“– Read

via "National Vulnerability Database".
⚠ Serious Security: Darkweb drugs market Hydra taken offline by German police ⚠

Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...

πŸ“– Read

via "Naked Security".
❀1πŸ‘1
⚠ S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast] ⚠

Latest episode - listen now! Cybersecurity news and advice in plain English.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-46416 β€Ό

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23900 β€Ό

A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46417 β€Ό

Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
❌ MacOS Malware: Myth vs. Truth – Podcast ❌

Huntress Labs R&D Director Jamie Levy busts the old β€œMacs don’t get viruses” myth and offers tips on how MacOS malware differs and how to protect against it.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Apple paid out $36,000 bug bounty for HTTP request smuggling flaws on core web apps – research πŸ—“οΈ

Queue poisoning attacks allegedly put accounts at risk of takeover

πŸ“– Read

via "The Daily Swig".
πŸ•΄ The Blurring Line, and Growing Risk, Between Physical and Digital Supply Chains πŸ•΄

Risk increases as the lines between physical and digital supply chains blur and the computing footprint expands.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Nearly Two-Thirds of Organizations Hit with Ransomware Paid Up in 2021 πŸ•΄

CyberEdge report contains data on the skills shortage, the hottest security tech in 2022, the weakest links of the year, specialty certifications in demand, and more.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Blumira Unveils Cloud SIEM With Integrated Detection and Response for SMBs πŸ•΄

Self-service cloud SIEM comes in free and paid editions.

πŸ“– Read

via "Dark Reading".
❌ SSRF Flaw in Fintech Platform Allowed for Compromise of Bank Accounts ❌

Researchers discovered the vulnerability in an API already integrated into many bank systems, which could have defrauded millions of users by giving attackers access to their funds.

πŸ“– Read

via "Threat Post".
πŸ‘1
πŸ—“οΈ Wake-up call: Is the infosec skills gap causing a mental health crisis? πŸ—“οΈ

Increasing workloads are causing depression and anxiety among frontline security staff, report claims

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2021-46418 β€Ό

An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-46419 β€Ό

An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1