πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-20770 β€Ό

On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.

πŸ“– Read

via "National Vulnerability Database".
πŸ” What Is the Defense Federal Acquisition Regulation Supplement (DFARS)? πŸ”

Learn more about what DFARS compliance means, who and what it applies to, and what the minimum requirements are for organizations to comply.

πŸ“– Read

via "".
πŸ•΄ Q&A: How China Is Exporting Tech-Based Authoritarianism Across the World πŸ•΄

The US has to adapt its own policies to counter the push, warns former DocuSign CEO and Under Secretary of State Keith Krach.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Releases Defender for SMBs πŸ•΄

Microsoft's stand-alone version of Defender for SMBs promises to help SecOps teams automate detection, response, and recovery.

πŸ“– Read

via "Dark Reading".
πŸ•΄ China-Backed Winnti APT Siphons Reams of US Trade Secrets in Sprawling Cyber-Espionage Attack πŸ•΄

Operation CuckooBees uncovered the state-sponsored group's sophisticated new tactics in a years-long campaign that hit more than 30 tech and manufacturing companies.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-30241 β€Ό

The jquery.json-viewer library through 1.4.0 for Node.js does not properly escape characters such as < in a JSON object, as demonstrated by a SCRIPT element.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29943 β€Ό

Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesystem. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS-5175, and versions 7.2.x in TPS-5201. Earlier versions of Talend Administration Center may also be impacted; users are encouraged to update to a supported version.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1584 β€Ό

Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29942 β€Ό

Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perform SSRF HTTP GET requests on URLs in the internal network. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS-5175, and versions 7.2.x in TPS-5201. Earlier versions of Talend Administration Center may also be impacted; users are encouraged to update to a supported version.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-25786 β€Ό

Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ GitHub to Developers: Turn on 2FA, or Lose Access πŸ•΄

All active GitHub users who contribute code will be required to enable at least one form of two-factor authentication by the end of 2023.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-30292 β€Ό

thread_call in sqbaselib.cpp in SQUIRREL 3.2 lacks a certain sq_reservestack call.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30284 β€Ό

In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments).

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-30288 β€Ό

Agoo through 2.14.2 does not reject GraphQL fragment spreads that form cycles, leading to an application crash.

πŸ“– Read

via "National Vulnerability Database".
⚠ Android monthly updates are out – critical bugs found in critical places! ⚠

Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...

πŸ“– Read

via "Naked Security".
⚠ World Password Day – the 1960s just called and gave you your passwords back ⚠

Yes, passwords are going away. No, it won't happen tomorrow. So it's still worth knowing the basics of picking proper passwords.

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Serious Snipe-IT bug exploitable to send password reset email traps πŸ—“οΈ

Attackers could use the flaw to steal credentials with no authentication required

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-1588 β€Ό

Cross-site Scripting (XSS) in GitHub repository contao/contao prior to 4.13.3. Attacker can execute Malicious JS in Application :)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28890 β€Ό

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ India to introduce six-hour data breach notification rule πŸ—“οΈ

Reporting window is 66 hours shorter than that stipulated under the EU’s GDPR

πŸ“– Read

via "The Daily Swig".
❌ VHD Ransomware Linked to North Korea’s Lazarus Group ❌

Source code and Bitcoin transactions point to the malware, which emerged in March 2020, being the work of APT38, researchers at Trellix said.

πŸ“– Read

via "Threat Post".