π΄ Vanity URLs Could be Spoofed for Social Engineering Attacks π΄
π Read
via "Dark Reading".
Attackers could abuse the vanity subdomains of popular cloud services such as Box.com, Google, and Zoom to mask attacks in phishing campaigns.π Read
via "Dark Reading".
Darkreading
Vanity URLs Could Be Spoofed for Social Engineering Attacks
Attackers could abuse the vanity subdomains of popular cloud services such as Box.com, Google, and Zoom to mask attacks in phishing campaigns.
π΄ The Danger of Online Data Brokers π΄
π Read
via "Dark Reading".
Enterprises should consider online data brokers as part of their risk exposure analysis if they don't already do so.π Read
via "Dark Reading".
Darkreading
The Danger of Online Data Brokers
Enterprises should consider online data brokers as part of their risk exposure analysis if they don't already do so.
π΄ Cyber-Espionage Attack Drops Post-Exploit Malware Framework on Microsoft Exchange Servers π΄
π Read
via "Dark Reading".
IceApple's 18 separate modules include those for data exfiltration, credential harvesting, and file and directory deletion, CrowdStrike warns.π Read
via "Dark Reading".
Dark Reading
Cyber-Espionage Attack Drops Post-Exploit Malware Framework on Microsoft Exchange Servers
IceApple's 18 separate modules include those for data exfiltration, credential harvesting, and file and directory deletion, CrowdStrike warns.
β Colonial Pipeline facing $1,000,000 fine for poor recovery plans β
π Read
via "Naked Security".
How good is your cybersecurity? Are you making the same mistakes as lots of other people? Here's some real-life advice...π Read
via "Naked Security".
Naked Security
Colonial Pipeline facing $1,000,000 fine for poor recovery plans
How good is your cybersecurity? Are you making the same mistakes as lots of other people? Hereβs some real-life adviceβ¦
βΌ CVE-2022-29316 βΌ
π Read
via "National Vulnerability Database".
Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29727 βΌ
π Read
via "National Vulnerability Database".
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-3254 βΌ
π Read
via "National Vulnerability Database".
Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29728 βΌ
π Read
via "National Vulnerability Database".
Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29318 βΌ
π Read
via "National Vulnerability Database".
An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29655 βΌ
π Read
via "National Vulnerability Database".
An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29656 βΌ
π Read
via "National Vulnerability Database".
Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29975 βΌ
π Read
via "National Vulnerability Database".
An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .π Read
via "National Vulnerability Database".
βΌ CVE-2020-19228 βΌ
π Read
via "National Vulnerability Database".
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29976 βΌ
π Read
via "National Vulnerability Database".
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .π Read
via "National Vulnerability Database".
βΌ CVE-2022-29317 βΌ
π Read
via "National Vulnerability Database".
Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.π Read
via "National Vulnerability Database".
π΄ SpyCloud Report: Fortune 1000 Employees Pose Elevated Cyber Risk to Companies π΄
π Read
via "Dark Reading".
Analysis finds 687 million exposed credentials and personally identifiable information (PII) among Fortune 1000 employees, and a 64% password reuse rate.π Read
via "Dark Reading".
Darkreading
SpyCloud Report: Fortune 1000 Employees Pose Elevated Cyber Risk to Companies
Analysis finds 687 million exposed credentials and personally identifiable information (PII) among Fortune 1000 employees, and a 64% password reuse rate.
ποΈ CyberUK 2022: Global power conflicts creating βbalkinizationβ of cybersecurity tech ποΈ
π Read
via "The Daily Swig".
Technology interoperability at risk from wider conflict between China and the Westπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
CyberUK 2022: Global power conflicts creating βbalkinizationβ of cybersecurity tech
Technology interoperability at risk from wider conflict between China and the West
βΌ CVE-2021-44167 βΌ
π Read
via "National Vulnerability Database".
An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log files and directories via symbolic links.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2022-27656 βΌ
π Read
via "National Vulnerability Database".
The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1622 βΌ
π Read
via "National Vulnerability Database".
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28214 βΌ
π Read
via "National Vulnerability Database".
During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systemsΓ’β¬β’ Confidentiality, Integrity, and Availability.π Read
via "National Vulnerability Database".