πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Firms Push for CVE-Like Cloud Bug System ❌

Researchers propose fresh approaches to cloud-security bugs and mitigating exposure, impact and risk.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-24706 β€Ό

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ SecurityScorecard Launches Cyber Risk Quantification Portfolio πŸ•΄

SecurityScorecard's Cyber Risk Quantification portfolio helps customers understand the financial impact of a cyber-attack.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Introducing Apostro: A Risk Management Platform for Web3 Security πŸ•΄

Apostro's system will monitor all transactions to identify malicious behavior that can cause damage to DeFi protocols.

πŸ“– Read

via "Dark Reading".
πŸ›  GNU Privacy Guard 2.2.35 πŸ› 

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions. This is the LTS release.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Mandos Encrypted File System Unattended Reboot Utility 1.8.15 πŸ› 

The Mandos system allows computers to have encrypted root file systems and at the same time be capable of remote or unattended reboots. The computers run a small client program in the initial RAM disk environment which will communicate with a server over a network. All network communication is encrypted using TLS. The clients are identified by the server using an OpenPGP key that is unique to each client. The server sends the clients an encrypted password. The encrypted password is decrypted by the clients using the same OpenPGP key, and the password is then used to unlock the root file system.

πŸ“– Read

via "Packet Storm Security".
πŸ›  GNU Privacy Guard 2.3.6 πŸ› 

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.

πŸ“– Read

via "Packet Storm Security".
πŸ‘1
πŸ•΄ Cyber Conflict Overshadowed a Major Government Ransomware Alert πŸ•΄

The FBI warns that ransomware targets are no longer predictably the biggest, richest organizations, and that attackers have leveled up to victimize organizations of all sizes.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Bug bounty platform Intigriti offers new hourly payment option for vulnerability researchers πŸ—“οΈ

Pentesting-meets-bug bounty model announced today

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-27469 β€Ό

Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27985 β€Ό

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27984 β€Ό

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27299 β€Ό

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27468 β€Ό

Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ API Attacks Soar Amid the Growing Application Surface Area πŸ•΄

With Web application programming interface (API) traffic growing quickly, the average cloud-focused company sees three times more attacks.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Disavowed: Chrome plans to deprecate β€˜document.domain’ lays the groundwork for shift in browser security πŸ—“οΈ

Making document.domain immutable

πŸ“– Read

via "The Daily Swig".
πŸ•΄ CISA Taps Veteran CISO Bob Lord for Technical Adviser Role πŸ•΄

Lord previously spearheaded security for the Democratic National Committee and held leadership roles at companies including Yahoo, Rapid7, and Twitter.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24882 β€Ό

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1173 β€Ό

stored xss in GitHub repository getgrav/grav prior to 1.7.33.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23942 β€Ό

Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24881 β€Ό

Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2.

πŸ“– Read

via "National Vulnerability Database".