πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24831 β€Ό

OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions prior to 3.16.1 are vulnerable to SQL injection due to the use of string concatenation to create SQL queries instead of prepared statements. No known workarounds exist. This issue has been patched in 3.16.1, 3.15.9, 3.14.1, and 3.13.1 and users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24830 β€Ό

OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vulnerable to path traversal in multiple endpoints, leading to arbitrary file read/write, and potential remote code execution. There are no known workarounds. This issue has been patched and users are recommended to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1379 β€Ό

URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How to Turn a Coke Can Into an Eavesdropping Device πŸ•΄

Cyber-researchers are testing the bounds of optical attacks with a technique that allows attackers to recover voice audio from meetings if there are shiny, lightweight objects nearby.

πŸ“– Read

via "Dark Reading".
πŸ€”1
β€Ό CVE-2021-41965 β€Ό

A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being performed.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
⚠ He sold cracked passwords for a living – now he’s serving 4 years in prison ⚠

Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...

πŸ“– Read

via "Naked Security".
❀2πŸ‘1
⚠ Firefox out-of-band update to 100.0.1 – just in time for Pwn2Own? ⚠

A new point-release of Firefox. Not unusual, but the timing of this one is interesting, with Pwn2Own coming up in a few days.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-30763 β€Ό

Janet before 1.22.0 mishandles arrays.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘2
β€Ό CVE-2022-30779 β€Ό

Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution via an unserialize pop chain in __destruct in GuzzleHttp\Cookie\FileCookieJar.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30778 β€Ό

Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution via an unserialize pop chain in __destruct in Illuminate\Broadcasting\PendingBroadcast.php and dispatch($command) in Illuminate\Bus\QueueingDispatcher.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30767 β€Ό

nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30775 β€Ό

xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30770 β€Ό

Terminalfour before 8.3.8 allows XSS, aka RDSM-31817. 8.2.18.2.1 and 8.2.18.5 are also fixed versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30765 β€Ό

Calibre-Web before 0.6.18 allows user table SQL Injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30781 β€Ό

Gitea before 1.6.7 does not escape git fetch remote.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Parker Hannifin reveals cyber-attack exposed sensitive employee data πŸ—“οΈ

Data breach involves Social Security numbers and health insurance data, among other information

πŸ“– Read

via "The Daily Swig".
πŸ‘1
❌ Microsoft’s May Patch Tuesday Updates Cause Windows AD Authentication Errors ❌

Microsoft's May Patch Tuesday update is triggering authentication errors.

πŸ“– Read

via "Threat Post".
πŸ“’ Panda Free Antivirus review: A free security tool with a personality all of its own πŸ“’

There's plenty to like here, including excellent malware protection, but this security package has some notable shortcomings

πŸ“– Read

via "ITPro".
πŸ“’ WannaCry's ghost is still wreaking havoc πŸ“’

A retooled version of the infamous ransomware strain continues to haunt corporate networks around the world

πŸ“– Read

via "ITPro".
πŸ“’ Windows Server admins say latest Patch Tuesday broke authentication policies πŸ“’

Microsoft has issued a workaround for the certificate-mapping issue, but many have already rolled back the updates to avoid operational disruption

πŸ“– Read

via "ITPro".
πŸ“’ The rise of double extortion ransomware πŸ“’

With the use of this tactic increasing, we look at how you can protect your business

πŸ“– Read

via "ITPro".