πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-30695 β€Ό

Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33025 β€Ό

xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33001 β€Ό

xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter Γ’β‚¬ΛœbdateÒ€ℒ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27444 β€Ό

The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ iPhones Open to Attack Even When Off, Researchers Say πŸ•΄

Wireless chips that run when the iPhone iOS is shut down can be exploited.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 50% of Orgs Rely on Email to Manage Security πŸ•΄

Even with dedicated identity management tools at their disposal, many companies β€” smaller ones especially β€” are sticking with email and spreadsheets for handling permissions.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ RF Technologies Releases Safe Place Staff Protection for Healthcare Settings πŸ•΄

RFT is expanding the Safe Place hospital market security system to include staff protection.

πŸ“– Read

via "Dark Reading".
πŸ•΄ TorchLight Expands Cybersecurity Services With MDR Sentinel in Partnership With Microsoft πŸ•΄

MDR Sentinel expands TorchLight’s leading managed detection and response (MDR) services with turnkey SIEM and SOAR capabilities from Microsoft; TorchLight also announces it attains elite Microsoft Gold Partner Status

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23665 β€Ό

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1586 β€Ό

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23662 β€Ό

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23659 β€Ό

A remote reflected cross site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23658 β€Ό

A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23661 β€Ό

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23667 β€Ό

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23660 β€Ό

A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23663 β€Ό

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23664 β€Ό

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23668 β€Ό

A remote authenticated server-side request forgery (ssrf) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manage that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1587 β€Ό

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23657 β€Ό

A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

πŸ“– Read

via "National Vulnerability Database".