π Friday Five 4/8 π
π Read
via "".
The takedown of a darknet powerhouse, cybercriminals getting more creative, how the most common insider cyber threats may not be quite what you suspect, and more β catch up on this weekβs news with the Friday Five!π Read
via "".
Digital Guardian
Friday Five 4/8
The takedown of a darknet powerhouse, cybercriminals getting more creative, how the most common insider cyber threats may not be quite what you suspect, and more β catch up on this weekβs news with the Friday Five!
βΌ CVE-2021-46437 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46436 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.π Read
via "National Vulnerability Database".
π΄ Security Nihilism Is Putting Your Company β and Its Employees β at Risk π΄
π Read
via "Dark Reading".
Some enterprise security tactics can backfire, pitting IT and security teams against the employees theyβre trying to protect.π Read
via "Dark Reading".
Dark Reading
Security Nihilism Is Putting Your Company β and Its Employees β at Risk
Some enterprise security tactics can backfire, pitting IT and security teams against the employees theyβre trying to protect.
βΌ CVE-2021-46367 βΌ
π Read
via "National Vulnerability Database".
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24229 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor.π Read
via "National Vulnerability Database".
ποΈ Third member of FIN7 cybercrime gang jailed over card skimming scheme ποΈ
π Read
via "The Daily Swig".
US authorities sentence pen tester to five years in prisonπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Third member of FIN7 cybercrime gang jailed over card skimming scheme
US authorities sentence pen tester to five years in prison
π΄ ByteChek Founder AJ Yawn Brings Discipline to Everything He Does π΄
π Read
via "Dark Reading".
Security Pro File: The former Army captain, whose security startup is on an upward trajectory, works hard to "make compliance suck less."π Read
via "Dark Reading".
Dark Reading
ByteChek Founder AJ Yawn Brings Discipline to Everything He Does
Security Pro File: The former Army captain, whose security startup is on an upward trajectory, works hard to "make compliance suck less."
β S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast] β
π Read
via "Naked Security".
Latest episode - listen now! Cybersecurity news and advice in plain English.π Read
via "Naked Security".
Naked Security
S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast]
Latest episode β listen now! Cybersecurity news and advice in plain English.
β Popular Ruby Asciidoc toolkit patched against critical vuln β get the update now! β
π Read
via "Naked Security".
A rogue line-continuation character can trick the code into validating just the second half of the line, but executing all of it.π Read
via "Naked Security".
Naked Security
Popular Ruby Asciidoc toolkit patched against critical vuln β get the update now!
A rogue line-continuation character can trick the code into validating just the second half of the line, but executing all of it.
β Google Play Bitten by Sharkbot Info-stealer βAV Solutionβ β
π Read
via "Threat Post".
Google removed six different malicious Android applications targeting mainly users in the U.K. and Italy that were installed about 15,000 times.π Read
via "Threat Post".
Threat Post
Google Play Bitten by Sharkbot Info-stealer βAV Solutionβ
Google removed six different malicious Android applications targeting mainly users in the U.K. and Italy that were installed about 15,000 times.
βΌ CVE-2021-41715 βΌ
π Read
via "National Vulnerability Database".
libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27044 βΌ
π Read
via "National Vulnerability Database".
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27046 βΌ
π Read
via "National Vulnerability Database".
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.π Read
via "National Vulnerability Database".
π OpenSSH 9.0p1 π
π Read
via "Packet Storm Security".
This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.π Read
via "Packet Storm Security".
Packetstormsecurity
OpenSSH 9.0p1 β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π1
βΌ CVE-2021-40656 βΌ
π Read
via "National Vulnerability Database".
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22339 βΌ
π Read
via "National Vulnerability Database".
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27148 βΌ
π Read
via "National Vulnerability Database".
GPAC mp4box 1.1.0-DEV-rev1663-g881c6a94a-master is vulnerable to Integer Overflow.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27147 βΌ
π Read
via "National Vulnerability Database".
GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_tag.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27047 βΌ
π Read
via "National Vulnerability Database".
mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27146 βΌ
π Read
via "National Vulnerability Database".
GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-overflow vulnerability in function gf_isom_apple_enum_tag.π Read
via "National Vulnerability Database".