πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38886 β€Ό

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38903 β€Ό

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 209691.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29582 β€Ό

In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29583 β€Ό

service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29589 β€Ό

Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ Early Discovery of Pipedream Malware a Success Story for Industrial Security πŸ•΄

Cybersecurity professionals discovered, analyzed, and created defenses against the ICS malware framework before it was deployed, but expect the stakes to keep rising.

πŸ“– Read

via "Dark Reading".
πŸ•΄ FBI Warns Ransomware Attacks on Agriculture Co-ops Could Upend Food Supply Chain πŸ•΄

Ransomware groups are looking to strike large agriculture cooperatives during strategic seasons, when they are most vulnerable, according to law enforcement.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Neustar Security Services’ UltraDNS Integrates Terraform for Streamlined, Automated DNS Management πŸ•΄

UltraDNS Terraform Provider enhances productivity, change management.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1440 β€Ό

Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow for any operating system command to be spawned by the attacker.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Sophos Buys Alert-Monitoring Automation Vendor πŸ•΄

Acquisition of cloud-based alert security company will help Sophos automate tasks bogging down security teams, the company says.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2021-3971 β€Ό

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27340 β€Ό

MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1108 β€Ό

A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0636 β€Ό

A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3970 β€Ό

A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27342 β€Ό

Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4210 β€Ό

A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0192 β€Ό

A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3972 β€Ό

A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27341 β€Ό

JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-1107 β€Ό

A potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

πŸ“– Read

via "National Vulnerability Database".