πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-27330 β€Ό

A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28785 β€Ό

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28790 β€Ό

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28793 β€Ό

Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27413 β€Ό

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28791 β€Ό

Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28780 β€Ό

Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28784 β€Ό

Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28783 β€Ό

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28781 β€Ό

Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20105 β€Ό

In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ What Should I Know About Defending IoT Attack Surfaces? πŸ•΄

The Internet of Things needs to be part of the overall corporate information security policy to prevent adversaries from using these devices as an entry point.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1555 β€Ό

DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1502 β€Ό

Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.

πŸ“– Read

via "National Vulnerability Database".
❌ Unpatched DNS Bug Puts Millions of Routers, IoT Devices at Risk ❌

A flaw in all versions of the popular C standard libraries uClibe and uClibe-ng can allow for DNS poisoning attacks against target devices.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ TLStorm 2.0: Millions of Aruba and Avaya network switches affected by RCE flaws πŸ—“οΈ

Patches issued for vulnerabilities arising from misuse of NanoSSL TLS library

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Aryaka, Carnegie Mellon’s CyLab to Research New Threat Mitigation Techniques πŸ•΄

The security research partnership will focus on developing new techniques and releasing them as open source.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1571 β€Ό

Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ...

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42192 β€Ό

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ State Bar of Georgia reels from cyber-attack πŸ—“οΈ

Bar suspends website after mystery assault

πŸ“– Read

via "The Daily Swig".
❌ Attackers Use Event Logs to Hide Fileless Malware ❌

A sophisticated campaign utilizes a novel anti-detection method.

πŸ“– Read

via "Threat Post".