πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-23900 β€Ό

A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46417 β€Ό

Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
❌ MacOS Malware: Myth vs. Truth – Podcast ❌

Huntress Labs R&D Director Jamie Levy busts the old β€œMacs don’t get viruses” myth and offers tips on how MacOS malware differs and how to protect against it.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Apple paid out $36,000 bug bounty for HTTP request smuggling flaws on core web apps – research πŸ—“οΈ

Queue poisoning attacks allegedly put accounts at risk of takeover

πŸ“– Read

via "The Daily Swig".
πŸ•΄ The Blurring Line, and Growing Risk, Between Physical and Digital Supply Chains πŸ•΄

Risk increases as the lines between physical and digital supply chains blur and the computing footprint expands.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Nearly Two-Thirds of Organizations Hit with Ransomware Paid Up in 2021 πŸ•΄

CyberEdge report contains data on the skills shortage, the hottest security tech in 2022, the weakest links of the year, specialty certifications in demand, and more.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Blumira Unveils Cloud SIEM With Integrated Detection and Response for SMBs πŸ•΄

Self-service cloud SIEM comes in free and paid editions.

πŸ“– Read

via "Dark Reading".
❌ SSRF Flaw in Fintech Platform Allowed for Compromise of Bank Accounts ❌

Researchers discovered the vulnerability in an API already integrated into many bank systems, which could have defrauded millions of users by giving attackers access to their funds.

πŸ“– Read

via "Threat Post".
πŸ‘1
πŸ—“οΈ Wake-up call: Is the infosec skills gap causing a mental health crisis? πŸ—“οΈ

Increasing workloads are causing depression and anxiety among frontline security staff, report claims

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2021-46418 β€Ό

An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-46419 β€Ό

An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ Keysight Delivers Zero Trust Test Solution πŸ•΄

Enables network equipment manufacturers to validate devices in distributed cloud networks.

πŸ“– Read

via "Dark Reading".
πŸ‘2
πŸ—“οΈ VMware patches critical flaws in Workspace ONE Access identity management software πŸ—“οΈ

Virtual reality

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Nord Security Raises First Outside Capital at $1.6B Valuation πŸ•΄

Financing raised from Novator Ventures, Burda Principal Investments, General Catalyst, and leading angel investors.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-27016 β€Ό

There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25339 β€Ό

ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25338 β€Ό

ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26627 β€Ό

Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Top Application Security Mitigations in Q1 of 2022 πŸ•΄

What is the best way to mitigate application security attacks? Learn how companies have mitigated the top threats.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23972 β€Ό

ASUS RT-AX56UÒ€ℒs SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22515 β€Ό

A remote, unauthenticated attacker could utilize the control programmer of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

πŸ“– Read

via "National Vulnerability Database".