πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Attackers Use Event Logs to Hide Fileless Malware ❌

A sophisticated campaign utilizes a novel anti-detection method.

πŸ“– Read

via "Threat Post".
πŸ›  Clam AntiVirus Toolkit 0.105.0 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ SAC Health System Impacted By Security Incident πŸ•΄

Six boxes of paper documents were removed from the facility without authorization in early March.

πŸ“– Read

via "Dark Reading".
πŸ•΄ AutoRABIT Secures $26M in Series B Investment from Full In Partners to Expand DevSecOps Platform πŸ•΄

AutoRABIT intends to direct the funding toward growth initiatives and product development.

πŸ“– Read

via "Dark Reading".
πŸ•΄ What Stars Wars Teaches Us About Threats πŸ•΄

The venerable film franchise shows us how to take threats in STRIDE.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Uptycs Announces New Cloud Identity and Entitlement Management (CIEM) Capabilities πŸ•΄

Also adds support for Google Cloud Platform (GCP) and Microsoft Azure, and PCI compliance coverage.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42185 β€Ό

wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28111 β€Ό

MyBatis PageHelper v1.x.x-v5.x.x was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28096 β€Ό

Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Zero-day bug in uClibc library could leave IoT devices vulnerable to DNS poisoning attacks πŸ—“οΈ

Unpatched flaw caused by the predictability of transaction IDs

πŸ“– Read

via "The Daily Swig".
⚠ Firefox hits 100*, fixes bugs… but no new zero-days this month ⚠

Despite concerns that some websites might break when Chromium and then Firefox reached version 100, the web still seems to be intact.

πŸ“– Read

via "Naked Security".
πŸ•΄ AI for Cybersecurity Shimmers With Promise, But Challenges Abound πŸ•΄

Companies see AI-powered cybersecurity tools and systems as the future, but at present nearly 90% of them say they face significant hurdles in making use of them.

πŸ“– Read

via "Dark Reading".
⚠ Android monthly updates are out – critical bugs found in critical places! ⚠

Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-29347 β€Ό

An arbitrary file upload vulnerability in Web@archiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28552 β€Ό

Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28081 β€Ό

A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to execute arbitrary web scripts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27903 β€Ό

An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25784 β€Ό

Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28512 β€Ό

A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28076 β€Ό

Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28487 β€Ό

Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.

πŸ“– Read

via "National Vulnerability Database".