πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25786 β€Ό

Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ GitHub to Developers: Turn on 2FA, or Lose Access πŸ•΄

All active GitHub users who contribute code will be required to enable at least one form of two-factor authentication by the end of 2023.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-30292 β€Ό

thread_call in sqbaselib.cpp in SQUIRREL 3.2 lacks a certain sq_reservestack call.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30284 β€Ό

In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments).

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-30288 β€Ό

Agoo through 2.14.2 does not reject GraphQL fragment spreads that form cycles, leading to an application crash.

πŸ“– Read

via "National Vulnerability Database".
⚠ Android monthly updates are out – critical bugs found in critical places! ⚠

Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...

πŸ“– Read

via "Naked Security".
⚠ World Password Day – the 1960s just called and gave you your passwords back ⚠

Yes, passwords are going away. No, it won't happen tomorrow. So it's still worth knowing the basics of picking proper passwords.

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Serious Snipe-IT bug exploitable to send password reset email traps πŸ—“οΈ

Attackers could use the flaw to steal credentials with no authentication required

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-1588 β€Ό

Cross-site Scripting (XSS) in GitHub repository contao/contao prior to 4.13.3. Attacker can execute Malicious JS in Application :)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28890 β€Ό

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ India to introduce six-hour data breach notification rule πŸ—“οΈ

Reporting window is 66 hours shorter than that stipulated under the EU’s GDPR

πŸ“– Read

via "The Daily Swig".
❌ VHD Ransomware Linked to North Korea’s Lazarus Group ❌

Source code and Bitcoin transactions point to the malware, which emerged in March 2020, being the work of APT38, researchers at Trellix said.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-41739 β€Ό

A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1592 β€Ό

Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1411 β€Ό

Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1590 β€Ό

A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45783 β€Ό

Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
❌ F5 Warns of Critical Bug Allowing Remote Code Execution in BIG-IP Systems ❌

The vulnerability is 'critical' with a CVSS severity rating of 9.8 out of 10.

πŸ“– Read

via "Threat Post".
❌ CANs Reinvent LANs for an All-Local World ❌

A close look at a new type of network, known as a Cloud Area Network.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Heroku resets user passwords after concluding April cyber-attack ran deep πŸ—“οΈ

Hack investigation blames compromised token for breach

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why Security Matters Even More in Online Gaming πŸ•΄

As the gaming sector booms, game publishers and gaming networks have been heavily targeted with distributed denial-of-service (DDoS) attacks in the last year.

πŸ“– Read

via "Dark Reading".