πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41965 β€Ό

A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being performed.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
⚠ He sold cracked passwords for a living – now he’s serving 4 years in prison ⚠

Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...

πŸ“– Read

via "Naked Security".
❀2πŸ‘1
⚠ Firefox out-of-band update to 100.0.1 – just in time for Pwn2Own? ⚠

A new point-release of Firefox. Not unusual, but the timing of this one is interesting, with Pwn2Own coming up in a few days.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-30763 β€Ό

Janet before 1.22.0 mishandles arrays.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘2
β€Ό CVE-2022-30779 β€Ό

Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution via an unserialize pop chain in __destruct in GuzzleHttp\Cookie\FileCookieJar.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30778 β€Ό

Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution via an unserialize pop chain in __destruct in Illuminate\Broadcasting\PendingBroadcast.php and dispatch($command) in Illuminate\Bus\QueueingDispatcher.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30767 β€Ό

nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30775 β€Ό

xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30770 β€Ό

Terminalfour before 8.3.8 allows XSS, aka RDSM-31817. 8.2.18.2.1 and 8.2.18.5 are also fixed versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30765 β€Ό

Calibre-Web before 0.6.18 allows user table SQL Injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30781 β€Ό

Gitea before 1.6.7 does not escape git fetch remote.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Parker Hannifin reveals cyber-attack exposed sensitive employee data πŸ—“οΈ

Data breach involves Social Security numbers and health insurance data, among other information

πŸ“– Read

via "The Daily Swig".
πŸ‘1
❌ Microsoft’s May Patch Tuesday Updates Cause Windows AD Authentication Errors ❌

Microsoft's May Patch Tuesday update is triggering authentication errors.

πŸ“– Read

via "Threat Post".
πŸ“’ Panda Free Antivirus review: A free security tool with a personality all of its own πŸ“’

There's plenty to like here, including excellent malware protection, but this security package has some notable shortcomings

πŸ“– Read

via "ITPro".
πŸ“’ WannaCry's ghost is still wreaking havoc πŸ“’

A retooled version of the infamous ransomware strain continues to haunt corporate networks around the world

πŸ“– Read

via "ITPro".
πŸ“’ Windows Server admins say latest Patch Tuesday broke authentication policies πŸ“’

Microsoft has issued a workaround for the certificate-mapping issue, but many have already rolled back the updates to avoid operational disruption

πŸ“– Read

via "ITPro".
πŸ“’ The rise of double extortion ransomware πŸ“’

With the use of this tactic increasing, we look at how you can protect your business

πŸ“– Read

via "ITPro".
πŸ“’ Lone Russian RAT operator rivals large gangs with Β£5 "passion project" πŸ“’

Researchers say the lone actor's success speaks to the growing complexity of the underground malware market

πŸ“– Read

via "ITPro".
πŸ“’ Tool that scans office software for vulnerabilities finds almost 100 in Word and Acrobat πŸ“’

Myriad flaws in Microsoft Word, Adobe Acrobat, and Foxit Reader were discovered as part of the research project that netted $22,000 in bug bounty rewards

πŸ“– Read

via "ITPro".
πŸ—“οΈ SharePoint RCE bug resurfaces three months after being patched by Microsoft πŸ—“οΈ

Deserialization vulnerabilities are hard to fix

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Me, My Digital Self, and I: Why Identity Is the Foundation of a Decentralized Future πŸ•΄

A decentralized future is a grand ideal, but secure management of private keys is the prerequisite to ensure the integrity of decentralized applications and services.

πŸ“– Read

via "Dark Reading".
πŸ‘2