πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-29040 β€Ό

Jenkins Git Parameter Plugin 0.9.15 and earlier does not escape the name and description of Git parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29042 β€Ό

Jenkins Job Generator Plugin 1.22 and earlier does not escape the name and description of Generator Parameter and Generator Choice parameters on Job Generator jobs' Build With Parameters views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29037 β€Ό

Jenkins CVS Plugin 2.19 and earlier does not escape the name and description of CVS Symbolic Name parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29048 β€Ό

A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Plugin 2.15.3 and earlier allows attackers to connect to an attacker-specified URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0436 β€Ό

Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Russian Group Sandworm Foiled in Attempt to Disrupt Ukraine Power Grid πŸ•΄

The attack involved use of a new version of Industroyer tool for manipulating industrial control systems.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Patches Windows Flaw Under Attack and Reported by NSA πŸ•΄

"Go patch your systems before" the exploit spreads more widely, ZDI warns.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Plans Windows Auto-Update Service for Enterprises πŸ•΄

Starting in July, the Windows Autopatch service will automatically patch all software bugs, including security updates, for Windows 10/11 Enterprise E3 customers, Microsoft says.

πŸ“– Read

via "Dark Reading".
πŸ” Four Changing International Data Protection Laws to Keep an Eye On πŸ”

Organizations need to keep in mind changes to international data protection law and how they affect compliance demands.

πŸ“– Read

via "".
πŸ•΄ Criminal IP Cybersecurity Search Engine Launches First Beta Test πŸ•΄

Criminal IP visualizes all IT assets connected to the Internet based on IP addresses held by companies and individuals.

πŸ“– Read

via "Dark Reading".
🀯1
πŸ•΄ United States Leads Seizure of One of the World’s Largest Hacker Forums and Arrests Administrator πŸ•΄

Court records unsealed Tuesday indicate that the United States recently obtained judicial authorization to seize three domains that long hosted the RaidForums website.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Datto to be Acquired by Kaseya for $6.2 Billion πŸ•΄

Funding led by Insight Partners.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Intertrust Adds Security for IoT Devices in Zero-Trust Architectures to Intertrust Platform πŸ•΄

New features provide for end-to-end security and interoperability between data operations and multivendor IoT devices.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1339 β€Ό

SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ African banking sector targeted by malware-based phishing campaign πŸ—“οΈ

Attackers use HTML smuggling techniques to hide malicious files in fake job opportunities

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2020-29653 β€Ό

Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27475 β€Ό

Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24308 β€Ό

Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to obtain sensitive information during the install process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43742 β€Ό

CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Identifying a Vulnerability in the SAP Software Supply Chain πŸ•΄

Make sure you're using the patch to block this supply chain attack.

πŸ“– Read

via "Dark Reading".
⚠ Hospital robot system gets five critical security holes patched ⚠

Fortunately, we're not talking about a robot revolution, or about hospital AI run amuck. But these bugs could lead to ransomware, or worse...

πŸ“– Read

via "Naked Security".