πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-28921 β€Ό

A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-30111 β€Ό

Due to the use of an insecure algorithm for rolling codes in MCK Smartlock 1.0, allows attackers to unlock the mechanism via replay attacks.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Pwn2Own Made Bug Hunting a Real Sport πŸ•΄

From a scrappy contest where hackers tried to win laptops, Pwn2Own has grown into a premier event that has helped normalize bug hunting.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA to Federal Agencies: Patch VMWare Products Now or Take Them Offline πŸ•΄

Last month attackers quickly reverse-engineered VMWare patches to launch RCE attacks. CISA warns it's going to happen again.

πŸ“– Read

via "Dark Reading".
πŸ•΄ MITRE Creates Framework for Supply Chain Security πŸ•΄

System of Trust includes data-driven metrics for evaluating the integrity of software, services, and suppliers.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-29230 β€Ό

Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross-Site Scripting (XSS) vulnerability where an arbitrary user is able to execute scripts on pages that are built with Hydrogen. This affects all versions of Hydrogen starting from version 0.10.0 to 0.18.0. This vulnerability is exploitable in applications whose hydrating data is user controlled. All Hydrogen users should upgrade their project to version 0.19.0. There is no current workaround, and users should update as soon as possible. Additionally, the Content Security Policy is not an effective mitigation for this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38944 β€Ό

IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 211236.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29229 β€Ό

CaSS is a Competency and Skills System. CaSS Library, (npm:cassproject) has a missing cryptographic step when storing cryptographic keys that can allow a server administrator access to an accountÒ€ℒs cryptographic keys. This affects CaSS servers using standalone username/password authentication, which uses a method that expects e2e cryptographic security of authorization credentials. The issue has been patched in 1.5.8, however, the vulnerable accounts are only resecured when the user next logs in using standalone authentication, as the data required to resecure the account is not available to the server. The issue may be mitigated by using SSO or client side certificates to log in. Please note that SSO and client side certificate authentication does not have this expectation of no-knowledge credential access, and cryptographic keys are available to the server administrator.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30991 β€Ό

HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1774 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30992 β€Ό

Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30994 β€Ό

Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30990 β€Ό

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30033 β€Ό

Tenda TX9 Pro V22.03.02.10 is vulnerable to Buffer Overflow via the functtion setIPv6Status() in httpd module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1771 β€Ό

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30993 β€Ό

Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1670 β€Ό

When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1183 β€Ό

On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Rogue cloud users could sabotage fellow off-prem tenants via critical Flux flaw πŸ—“οΈ

Mischief-makers could β€˜disrupt the availability, integrity and confidentiality’ of other tenants

πŸ“– Read

via "The Daily Swig".
❌ Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover ❌

Privilege escalation flaw discovered in the Jupiter and JupiterX Core Plugin affects more than 90,000 sites.

πŸ“– Read

via "Threat Post".
πŸ•΄ Phishing Attacks for Initial Access Surged 54% in Q1 πŸ•΄

For the first time in a year, security incidents involving email compromises surpassed ransomware incidents, a new analysis shows.

πŸ“– Read

via "Dark Reading".