πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-0314 β€Ό

The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0969 β€Ό

The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1008 β€Ό

The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0271 β€Ό

The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24986 β€Ό

The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27041 β€Ό

Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0471 β€Ό

The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27111 β€Ό

Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Access control vulnerability in Easy!Appointments platform exposed sensitive personal data πŸ—“οΈ

Unprotected API could expose names, places, times of bookings made using app

πŸ“– Read

via "The Daily Swig".
⚠ Popular Ruby Asciidoc toolkit patched against critical vuln – get the update now! ⚠

A rogue line-continuation character can trick the code into validating just the second half of the line, but executing all of it.

πŸ“– Read

via "Naked Security".
πŸ•΄ Creating a Security Culture Where People Can Admit Mistakes πŸ•΄

In cybersecurity, user error is the symptom, not the disease. A healthy culture acknowledges and addresses the underlying causes of lapses.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 10 Signs of a Good Security Leader πŸ•΄

Strong leadership can lead to motivated and loyal employees. Here's what that looks like.

πŸ“– Read

via "Dark Reading".
⚠ OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default ⚠

Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?

πŸ“– Read

via "Naked Security".
πŸ•΄ SafeGuard Cyber Provides Security Advice for Defending Against Browser-in-the-Browser (BitB) Attacks πŸ•΄



πŸ“– Read

via "Dark Reading".
πŸ•΄ Imprivata Acquires SecureLink to Deliver a Single-Vendor Platform to Manage and Secure All Enterprise and Third-Party Digital Identities πŸ•΄

Imprivata will unlock further value for customers by unifying, integrating, and automating digital identity to enable autonomous identity systems.

πŸ“– Read

via "Dark Reading".
❌ Microsoft Takes Down Domains Used in Cyberattack Against Ukraine ❌

The APT28 (Advanced persistence threat) is operating since 2009, this group has worked under different names such as Sofacy, Sednit, Strontium Storm, Fancy Bear, Iron Twilight, and Pawn.

πŸ“– Read

via "Threat Post".
πŸ›  Haveged 1.9.18 πŸ› 

haveged is a daemon that feeds the /dev/random pool on Linux using an adaptation of the HArdware Volatile Entropy Gathering and Expansion algorithm invented at IRISA. The algorithm is self-tuning on machines with cpuid support, and has been tested in both 32-bit and 64-bit environments. The tarball uses the GNU build mechanism, and includes self test targets and a spec file for those who want to build an RPM.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2021-40219 β€Ό

Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38930 β€Ό

IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43442 β€Ό

A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 151106 (Ax68), and V5.0.9 build 150615 (Ax78) due to a failure to allow the creation of more than one administrator account; however, this can be bypassed by parameter maniulation using PUT and DELETE and by calling the 'UserPermission' endpoint with the ID of created account and set it to 'admin' userType, successfully adding a second administrative account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37293 β€Ό

A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php.

πŸ“– Read

via "National Vulnerability Database".