πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 2022: The Year Zero Trust Becomes Mainstream πŸ•΄

It has never been more important for organizations of all sizes to prioritize securing their users and their infrastructure secrets with zero-trust network access.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Senators Urge FTC to Probe ID.me Over Selfie Data β™ŸοΈ

Some of more tech-savvy Democrats in the U.S. Senate are asking the Federal Trade Commission (FTC) to investigate identity-proofing company ID.me for "deceptive statements" the company and its founder allegedly made over how they handle facial recognition data collected on behalf of the Internal Revenue Service, which until recently required anyone seeking a new IRS account online to provide a live video selfie to ID.me.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ The Industry Must Better Secure Open Source Code From Threat Actors πŸ•΄

Build security in up front to secure open source code at the foundational level. Apply security controls, have engineering teams test, do code review, and use attacker-centric behavioral analytics to mitigate threats.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA: Unpatched F5 BIG-IP Devices Under Active Attack πŸ•΄

Publicly released proof-of-concept exploits are supercharging attacks against unpatched systems, CISA warns.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-3956 β€Ό

A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports Ò€œunauthenticated bindҀ�, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only Ò€œauthenticated bindҀ� and/or Ò€œanonymous bindҀ� are not affected.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-0883 β€Ό

SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22786 β€Ό

The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22785 β€Ό

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1767 β€Ό

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1110 β€Ό

A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42852 β€Ό

A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28917 β€Ό

Tenda AX12 v22.03.01.21_cn was discovered to contain a stack overflow via the lanIp parameter in /goform/AdvSetLanIp.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42848 β€Ό

An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25161 β€Ό

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-xMy/z(x=32,64,96, y=T,R, z=D,DSS) versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DSS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MR/DS-TS versions prior to 1.270 and Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/z(x=24,40,60, y=T,R, z=ES,ESS) versions prior to 1.030 allows a remote unauthenticated attacker to cause a DoS condition for the product's program execution or communication by sending specially crafted packets. System reset of the product is required for recovery.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22776 β€Ό

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using these vulnerabilities requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42851 β€Ό

A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22778 β€Ό

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42704 β€Ό

Inkscape version 0.19 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28924 β€Ό

An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive information via a crafted GET request to the endpoint /api/students/me/courses/.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1734 β€Ό

A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30105 β€Ό

In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.

πŸ“– Read

via "National Vulnerability Database".