πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24041 β€Ό

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application stores the PBKDF2 derived key of users passwords with a low iteration count. An attacker with user profile access privilege can retrieve the stored password hashes of other accounts and then successfully perform an offline cracking attack and recover the plaintext passwords of other users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42581 β€Ό

Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24039 β€Ό

A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The Ò€œaddCellҀ� JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document, such that it is possible to inject arbitrary content (e.g., XML tags) into the generated file. An attacker with restricted privileges, by poisoning any of the content used to generate XLS reports, could be able to leverage the application to deliver malicious files against higher-privileged users and obtain Remote Code Execution (RCE) against the administratorÒ€ℒs workstation.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ—“οΈ Russia behind cyber-attack on satellite internet network KA-SAT that disrupted Ukrainian infrastructure – EU πŸ—“οΈ

Suspected DDoS attack took place one hour before Russia invaded Ukraine

πŸ“– Read

via "The Daily Swig".
❌ Hackers Actively Exploit F5 BIG-IP Bug ❌

The bug has a severe rating of 9.8, public exploits are released.

πŸ“– Read

via "Threat Post".
πŸ•΄ Mastering the New CISO Playbook πŸ•΄

How can you safeguard your organization amid global conflict and uncertainty?

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42645 β€Ό

CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28110 β€Ό

Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29591 β€Ό

Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43094 β€Ό

An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.

πŸ“– Read

via "National Vulnerability Database".
⚠ RubyGems supply chain rip-and-replace bug fixed – check your logs! ⚠

Imagine if you could assume the identity of, say, Franklin Delano Roosevelt simply by showing up and calling yourself "Frank".

πŸ“– Read

via "Naked Security".
πŸ—“οΈ UK government blocked four times as many cyber-scams in 2021 than previous year, CyberUK delegates told πŸ—“οΈ

War in Ukraine and ransomware trends top the agenda at this year’s NCSC-led conference

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Onapsis Announces New Offering to Jumpstart Security for SAP Customers πŸ•΄

Company delivers new vulnerability management offering to help resource-constrained organizations combat increasing attacks on mission-critical SAP applications .

πŸ“– Read

via "Dark Reading".
πŸ•΄ 5-Buck DCRat Malware Foretells a Worrying Cyber Future πŸ•΄

The Dark Crystal remote access Trojan (aka DCRat) breaks a few stereotypes, with coding done by a solo developer, using an obscure Web language and offering it at a frighteningly low price.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Arctic Wolf Launches Arctic Wolf Labs Focused on Security Operations Research and Intelligence Reporting πŸ•΄

New research-focused division focused on advancing innovation in the field of security operations.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybercriminals Are Increasingly Exploiting Vulnerabilities in Windows Print Spooler πŸ•΄

Kaspersky researchers discovered that cybercriminals made approximately 65,000 attacks between July 2021 and April 2022.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-26987 β€Ό

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28909 β€Ό

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx parameter in /setting/setWebWlanIdx.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28907 β€Ό

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28901 β€Ό

A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29325 β€Ό

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.

πŸ“– Read

via "National Vulnerability Database".