πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Criminal IP Cybersecurity Search Engine Launches First Beta Test πŸ•΄

Criminal IP visualizes all IT assets connected to the Internet based on IP addresses held by companies and individuals.

πŸ“– Read

via "Dark Reading".
🀯1
πŸ•΄ United States Leads Seizure of One of the World’s Largest Hacker Forums and Arrests Administrator πŸ•΄

Court records unsealed Tuesday indicate that the United States recently obtained judicial authorization to seize three domains that long hosted the RaidForums website.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Datto to be Acquired by Kaseya for $6.2 Billion πŸ•΄

Funding led by Insight Partners.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Intertrust Adds Security for IoT Devices in Zero-Trust Architectures to Intertrust Platform πŸ•΄

New features provide for end-to-end security and interoperability between data operations and multivendor IoT devices.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1339 β€Ό

SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ African banking sector targeted by malware-based phishing campaign πŸ—“οΈ

Attackers use HTML smuggling techniques to hide malicious files in fake job opportunities

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2020-29653 β€Ό

Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27475 β€Ό

Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24308 β€Ό

Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to obtain sensitive information during the install process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43742 β€Ό

CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Identifying a Vulnerability in the SAP Software Supply Chain πŸ•΄

Make sure you're using the patch to block this supply chain attack.

πŸ“– Read

via "Dark Reading".
⚠ Hospital robot system gets five critical security holes patched ⚠

Fortunately, we're not talking about a robot revolution, or about hospital AI run amuck. But these bugs could lead to ransomware, or worse...

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Git security vulnerabilities prompt updates πŸ—“οΈ

Windows users at highest risk from security bugs in software development tool

πŸ“– Read

via "The Daily Swig".
❌ Feds Shut Down RaidForums Hacking Marketplace ❌

The DoJ is charging its founder, 21-year-old Portuguese citizen Diogo Santos Coelho, on six criminal counts, including conspiracy, access device fraud and aggravated identity theft.

πŸ“– Read

via "Threat Post".
β™ŸοΈ Microsoft Patch Tuesday, April 2022 Edition β™ŸοΈ

Microsoft on Tuesday released updates to fix roughly 120 security vulnerabilities in its Windows operating systems and other software. Two of the flaws have been publicly detailed prior to this week, and one is already seeing active exploitation, according to a report from the U.S. National Security Agency (NSA).

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2022-28052 β€Ό

Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46167 β€Ό

An access control issue in the authentication module of wizplat PD065 v1.19 allows attackers to access sensitive data and cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26144 β€Ό

An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43741 β€Ό

CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27256 β€Ό

An open redirect vulnerability in Hubzilla before version 7.2 allows remote attackers to redirect a logged in user to an arbitrary URL via the rpath parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26643 β€Ό

An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.

πŸ“– Read

via "National Vulnerability Database".