βΌ CVE-2022-30288 βΌ
π Read
via "National Vulnerability Database".
Agoo through 2.14.2 does not reject GraphQL fragment spreads that form cycles, leading to an application crash.π Read
via "National Vulnerability Database".
β Android monthly updates are out β critical bugs found in critical places! β
π Read
via "Naked Security".
Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...π Read
via "Naked Security".
Naked Security
Android monthly updates are out β critical bugs found in critical places!
Android May 2022 updates are out β with some critical fixes in some critical places. Learn moreβ¦
β World Password Day β the 1960s just called and gave you your passwords back β
π Read
via "Naked Security".
Yes, passwords are going away. No, it won't happen tomorrow. So it's still worth knowing the basics of picking proper passwords.π Read
via "Naked Security".
Naked Security
World Password Day β the 1960s just called and gave you your passwords back
Yes, passwords are going away. No, it wonβt happen tomorrow. So itβs still worth knowing the basics of picking proper passwords.
ποΈ Serious Snipe-IT bug exploitable to send password reset email traps ποΈ
π Read
via "The Daily Swig".
Attackers could use the flaw to steal credentials with no authentication requiredπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Serious Snipe-IT bug exploitable to send password reset email traps
Attackers could use the flaw to steal credentials with no authentication required
βΌ CVE-2022-1588 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) in GitHub repository contao/contao prior to 4.13.3. Attacker can execute Malicious JS in Application :)π Read
via "National Vulnerability Database".
βΌ CVE-2022-28890 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.π Read
via "National Vulnerability Database".
ποΈ India to introduce six-hour data breach notification rule ποΈ
π Read
via "The Daily Swig".
Reporting window is 66 hours shorter than that stipulated under the EUβs GDPRπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
India to introduce six-hour data breach notification rule
Reporting window is 66 hours shorter than that stipulated under the EUβs GDPR
β VHD Ransomware Linked to North Koreaβs Lazarus Group β
π Read
via "Threat Post".
Source code and Bitcoin transactions point to the malware, which emerged in March 2020, being the work of APT38, researchers at Trellix said.π Read
via "Threat Post".
Threat Post
VHD Ransomware Linked to North Koreaβs Lazarus Group
Source code and Bitcoin transactions point to the malware, which emerged in March 2020, being the work of APT38, researchers at Trellix said.
βΌ CVE-2021-41739 βΌ
π Read
via "National Vulnerability Database".
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1592 βΌ
π Read
via "National Vulnerability Database".
Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...π Read
via "National Vulnerability Database".
βΌ CVE-2022-1411 βΌ
π Read
via "National Vulnerability Database".
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1590 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit has been disclosed to the public and may be used.π Read
via "National Vulnerability Database".
βΌ CVE-2021-45783 βΌ
π Read
via "National Vulnerability Database".
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.π Read
via "National Vulnerability Database".
β F5 Warns of Critical Bug Allowing Remote Code Execution in BIG-IP Systems β
π Read
via "Threat Post".
The vulnerability is 'critical' with a CVSS severity rating of 9.8 out of 10.π Read
via "Threat Post".
Threat Post
F5 Warns of Critical Bug Allowing Remote Code Execution in BIG-IP Systems
The vulnerability is 'critical' with a CVSS severity rating of 9.8 out of 10.
β CANs Reinvent LANs for an All-Local World β
π Read
via "Threat Post".
A close look at a new type of network, known as a Cloud Area Network.π Read
via "Threat Post".
Threat Post
CANs Reinvent LANs for an All-Local World
A close look at a new type of network, known as a Cloud Area Network.
ποΈ Heroku resets user passwords after concluding April cyber-attack ran deep ποΈ
π Read
via "The Daily Swig".
Hack investigation blames compromised token for breachπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Heroku resets user passwords after concluding April cyber-attack ran deep
Hack investigation blames compromised token for breach
π΄ Why Security Matters Even More in Online Gaming π΄
π Read
via "Dark Reading".
As the gaming sector booms, game publishers and gaming networks have been heavily targeted with distributed denial-of-service (DDoS) attacks in the last year.π Read
via "Dark Reading".
Darkreading
Why Security Matters Even More in Online Gaming
As the gaming sector booms, game publishers and gaming networks have been heavily targeted with distributed denial-of-service (DDoS) attacks in the last year.
β S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms [Podcast] β
π Read
via "Naked Security".
Latest episode - listen now!π Read
via "Naked Security".
Naked Security
S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms [Podcast]
Latest episode β listen now!
βΌ CVE-2022-28462 βΌ
π Read
via "National Vulnerability Database".
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29939 βΌ
π Read
via "National Vulnerability Database".
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29938 βΌ
π Read
via "National Vulnerability Database".
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.π Read
via "National Vulnerability Database".