πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1555 β€Ό

DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1502 β€Ό

Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.

πŸ“– Read

via "National Vulnerability Database".
❌ Unpatched DNS Bug Puts Millions of Routers, IoT Devices at Risk ❌

A flaw in all versions of the popular C standard libraries uClibe and uClibe-ng can allow for DNS poisoning attacks against target devices.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ TLStorm 2.0: Millions of Aruba and Avaya network switches affected by RCE flaws πŸ—“οΈ

Patches issued for vulnerabilities arising from misuse of NanoSSL TLS library

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Aryaka, Carnegie Mellon’s CyLab to Research New Threat Mitigation Techniques πŸ•΄

The security research partnership will focus on developing new techniques and releasing them as open source.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1571 β€Ό

Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ...

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42192 β€Ό

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ State Bar of Georgia reels from cyber-attack πŸ—“οΈ

Bar suspends website after mystery assault

πŸ“– Read

via "The Daily Swig".
❌ Attackers Use Event Logs to Hide Fileless Malware ❌

A sophisticated campaign utilizes a novel anti-detection method.

πŸ“– Read

via "Threat Post".
πŸ›  Clam AntiVirus Toolkit 0.105.0 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ SAC Health System Impacted By Security Incident πŸ•΄

Six boxes of paper documents were removed from the facility without authorization in early March.

πŸ“– Read

via "Dark Reading".
πŸ•΄ AutoRABIT Secures $26M in Series B Investment from Full In Partners to Expand DevSecOps Platform πŸ•΄

AutoRABIT intends to direct the funding toward growth initiatives and product development.

πŸ“– Read

via "Dark Reading".
πŸ•΄ What Stars Wars Teaches Us About Threats πŸ•΄

The venerable film franchise shows us how to take threats in STRIDE.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Uptycs Announces New Cloud Identity and Entitlement Management (CIEM) Capabilities πŸ•΄

Also adds support for Google Cloud Platform (GCP) and Microsoft Azure, and PCI compliance coverage.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42185 β€Ό

wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28111 β€Ό

MyBatis PageHelper v1.x.x-v5.x.x was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28096 β€Ό

Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Zero-day bug in uClibc library could leave IoT devices vulnerable to DNS poisoning attacks πŸ—“οΈ

Unpatched flaw caused by the predictability of transaction IDs

πŸ“– Read

via "The Daily Swig".
⚠ Firefox hits 100*, fixes bugs… but no new zero-days this month ⚠

Despite concerns that some websites might break when Chromium and then Firefox reached version 100, the web still seems to be intact.

πŸ“– Read

via "Naked Security".
πŸ•΄ AI for Cybersecurity Shimmers With Promise, But Challenges Abound πŸ•΄

Companies see AI-powered cybersecurity tools and systems as the future, but at present nearly 90% of them say they face significant hurdles in making use of them.

πŸ“– Read

via "Dark Reading".
⚠ Android monthly updates are out – critical bugs found in critical places! ⚠

Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...

πŸ“– Read

via "Naked Security".