πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Data Transformation: 3 Sessions to Attend at RSA 2022 πŸ•΄

Three RSA 2022 sessions take deep dives into the security considerations around data cloud transformation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-22983 β€Ό

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30372 β€Ό

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42969 β€Ό

Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30371 β€Ό

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30370 β€Ό

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30374 β€Ό

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/?page=transactions/manage_transaction&id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42967 β€Ό

Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29383 β€Ό

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30489 β€Ό

WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30373 β€Ό

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/manage_cargo_type.php?id=.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again) [Podcast] ⚠

Latest episode - lots to learn - plain English - fun with a serious side - listen now!

πŸ“– Read

via "Naked Security".
⚠ Serious Security: Learning from curl’s latest bug update ⚠

Learn how to write plain-speaking and purposeful security advisories from one of the most widely-used open source tools in the world.

πŸ“– Read

via "Naked Security".
⚠ He cracked passwords for a living – now he’s serving 4 years in prison ⚠

Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...

πŸ“– Read

via "Naked Security".
πŸ•΄ Log4Shell Exploit Threatens Enterprise Data Lakes, AI Poisoning πŸ•΄

A brand-new attack vector lays open enterprise data lakes, threatening grave consequences for AI use cases like telesurgery or autonomous cars.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Black Hat Asia: β€˜If democracy is to survive, technology will have to be tamed’ πŸ—“οΈ

Indian tech policy expert Samir Saran says it’s not too late to β€˜course-correct’ after a β€˜challenging decade’ for liberal democracies

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-28827 β€Ό

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29790 β€Ό

The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28826 β€Ό

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29794 β€Ό

The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30386 β€Ό

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.

πŸ“– Read

via "National Vulnerability Database".