πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-30781 β€Ό

Gitea before 1.6.7 does not escape git fetch remote.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Parker Hannifin reveals cyber-attack exposed sensitive employee data πŸ—“οΈ

Data breach involves Social Security numbers and health insurance data, among other information

πŸ“– Read

via "The Daily Swig".
πŸ‘1
❌ Microsoft’s May Patch Tuesday Updates Cause Windows AD Authentication Errors ❌

Microsoft's May Patch Tuesday update is triggering authentication errors.

πŸ“– Read

via "Threat Post".
πŸ“’ Panda Free Antivirus review: A free security tool with a personality all of its own πŸ“’

There's plenty to like here, including excellent malware protection, but this security package has some notable shortcomings

πŸ“– Read

via "ITPro".
πŸ“’ WannaCry's ghost is still wreaking havoc πŸ“’

A retooled version of the infamous ransomware strain continues to haunt corporate networks around the world

πŸ“– Read

via "ITPro".
πŸ“’ Windows Server admins say latest Patch Tuesday broke authentication policies πŸ“’

Microsoft has issued a workaround for the certificate-mapping issue, but many have already rolled back the updates to avoid operational disruption

πŸ“– Read

via "ITPro".
πŸ“’ The rise of double extortion ransomware πŸ“’

With the use of this tactic increasing, we look at how you can protect your business

πŸ“– Read

via "ITPro".
πŸ“’ Lone Russian RAT operator rivals large gangs with Β£5 "passion project" πŸ“’

Researchers say the lone actor's success speaks to the growing complexity of the underground malware market

πŸ“– Read

via "ITPro".
πŸ“’ Tool that scans office software for vulnerabilities finds almost 100 in Word and Acrobat πŸ“’

Myriad flaws in Microsoft Word, Adobe Acrobat, and Foxit Reader were discovered as part of the research project that netted $22,000 in bug bounty rewards

πŸ“– Read

via "ITPro".
πŸ—“οΈ SharePoint RCE bug resurfaces three months after being patched by Microsoft πŸ—“οΈ

Deserialization vulnerabilities are hard to fix

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Me, My Digital Self, and I: Why Identity Is the Foundation of a Decentralized Future πŸ•΄

A decentralized future is a grand ideal, but secure management of private keys is the prerequisite to ensure the integrity of decentralized applications and services.

πŸ“– Read

via "Dark Reading".
πŸ‘2
β€Ό CVE-2022-30011 β€Ό

In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30012 β€Ό

In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ UK government sits out bug bounty boom but welcomes vulnerability disclosure πŸ—“οΈ

Budget constraints limit any immediate ambitions

πŸ“– Read

via "The Daily Swig".
πŸ•΄ US Cyber Director: Forging a Cybersecurity Social Contract Is Not Optional πŸ•΄

In a Black Hat Asia keynote Fireside Chat, US National Cyber Director Chris Inglis outlined his vision of an effective cybersecurity public-private partnership strategy.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42897 β€Ό

A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29623 β€Ό

An arbitrary file upload vulnerability in the file upload module of Connect-Multiparty v2.2.0 allows attackers to execute arbitrary code via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1418 β€Ό

The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0873 β€Ό

The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1409 β€Ό

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1713 β€Ό

SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

πŸ“– Read

via "National Vulnerability Database".