πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-28874 β€Ό

Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker.

πŸ“– Read

via "National Vulnerability Database".
❌ Zero Trust for Data Helps Enterprises Detect, Respond and Recover from Breaches ❌

Mohit Tiwari, CEO of Symmetry Systems, explores Zero Trust, data objects and the NIST framework for cloud and on-prem environments.

πŸ“– Read

via "Threat Post".
⚠ Clearview AI face-matching service fined a lot less than expected ⚠

The fine has finally gone through... but it's less than 45% of what was originally proposed.

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Blockchain bridge Wormhole pays record $10m bug bounty reward πŸ—“οΈ

Critical security flaw patched on the same day it was submitted

πŸ“– Read

via "The Daily Swig".
πŸ•΄ After the Okta Breach, Diversify Your Sources of Truth πŸ•΄

What subsequent protections do you have in place when your first line of defense goes down?

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Yik Yak fixes information disclosure bug that leaked users’ GPS location πŸ—“οΈ

Hairy MitM exploit independently discovered by two security researchers

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-1817 β€Ό

A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="alert(1)"><td>1 leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1816 β€Ό

A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input <script>alert(1)</script> leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1810 β€Ό

Improper Access Control in GitHub repository publify/publify prior to 9.2.9.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Valeo Networks Acquires Next I.T. πŸ•΄

Next I.T. is the sixth and largest acquisition to date for Valeo Networks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Kingston Digital Releases Touch-Screen Hardware-Encrypted External SSD for Data Protection πŸ•΄

IronKey Vault Privacy 80 External SSD safeguards against brute-force attacks and BadUSB with digitally-signed firmware.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Chicago Public Schools data breach blamed on ransomware attack on supplier πŸ—“οΈ

Cybercrooks compromised server containing student course information and assessment data

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-28997 β€Ό

CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0900 β€Ό

A Stored Cross-Site Scripting (XSS) vulnerability in DivvyDrive's "aciklama" parameter could allow anyone to gain users' session informations.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28998 β€Ό

Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Pwn2Own Vancouver: 15th annual hacking event pays out $1.2m for high-impact security bugs πŸ—“οΈ

Tesla, Microsoft, and others targeted in hacking competition that saw Star Labs crowned β€˜Masters of Pwn’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why the Employee Experience Is Cyber Resilience πŸ•΄

A culture of trust, combined with tools designed around EX, can work in tandem to help organizations become more resilient and secure.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-29004 β€Ό

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29005 β€Ό

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41714 β€Ό

In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1811 β€Ό

Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.

πŸ“– Read

via "National Vulnerability Database".