πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-29821 β€Ό

In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29818 β€Ό

In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29819 β€Ό

In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29820 β€Ό

In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1509 β€Ό

Sed Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ A Peek into Visa's AI Tools Against Fraud πŸ•΄

Visa has invested heavily in data analytics and artificial intelligence over the past five years to secure the movement of money and keep fraud rates low.

πŸ“– Read

via "Dark Reading".
⚠ Ransomware Survey 2022 – like the Curate’s Egg, β€œgood in parts” ⚠

You might not like the headline statistics in this year's ransomware report... but that makes it even more important to take a look!

πŸ“– Read

via "Naked Security".
❌ Cyberattacks Rage in Ukraine, Support Military Operations ❌

At least five APTs are believed involved with attacks tied ground campaigns and designed to damage Ukraine's digital infrastructure.

πŸ“– Read

via "Threat Post".
❌ Attacker Breach β€˜Dozens’ of GitHub Repos Using Stolen OAuth Tokens ❌

GitHub shared the timeline of breaches in April 2022, this timeline encompasses the information related to when a threat actor gained access and stole private repositories belonging to dozens of organizations.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep80: Ransomware news, phishing woes, NAS bugs, and a giant hole in Java [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Socket: New tool takes a proactive approach to prevent OSS supply chain attacks πŸ—“οΈ

Signal detector aims to help developers to stay ahead of threats

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-29152 β€Ό

The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41921 β€Ό

novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24935 β€Ό

Lexmark products through 2022-02-10 have Incorrect Access Control.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Explainable AI for Fraud Prevention πŸ•΄

As the use of AI- and ML-driven decision-making draws transparency concerns, the need increases for explainability, especially when machine learning models appear in high-risk environments.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-43930 β€Ό

Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28101 β€Ό

Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22782 β€Ό

The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue during the installer repair operation. A malicious actor could utilize this to potentially delete system level files or folders, causing integrity or availability issues on the userÒ€ℒs host machine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43932 β€Ό

Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24879 β€Ό

Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22781 β€Ό

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting userÒ€ℒs currently installed version to a less secure version.

πŸ“– Read

via "National Vulnerability Database".