βΌ CVE-2022-28998 βΌ
π Read
via "National Vulnerability Database".
Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code.π Read
via "National Vulnerability Database".
ποΈ Pwn2Own Vancouver: 15th annual hacking event pays out $1.2m for high-impact security bugs ποΈ
π Read
via "The Daily Swig".
Tesla, Microsoft, and others targeted in hacking competition that saw Star Labs crowned βMasters of Pwnβπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Pwn2Own Vancouver: 15th annual hacking event pays out $1.2m for high-impact security bugs
Tesla, Microsoft, and others targeted in hacking competition that saw Star Labs crowned βMasters of Pwnβ
π΄ Why the Employee Experience Is Cyber Resilience π΄
π Read
via "Dark Reading".
A culture of trust, combined with tools designed around EX, can work in tandem to help organizations become more resilient and secure.π Read
via "Dark Reading".
Dark Reading
Why the Employee Experience Is Cyber Resilience
A culture of trust, combined with tools designed around employee experience, can work in tandem to help organizations become more resilient and secure.
βΌ CVE-2022-29004 βΌ
π Read
via "National Vulnerability Database".
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29005 βΌ
π Read
via "National Vulnerability Database".
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.π Read
via "National Vulnerability Database".
βΌ CVE-2021-41714 βΌ
π Read
via "National Vulnerability Database".
In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1811 βΌ
π Read
via "National Vulnerability Database".
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30017 βΌ
π Read
via "National Vulnerability Database".
Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30014 βΌ
π Read
via "National Vulnerability Database".
Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30016 βΌ
π Read
via "National Vulnerability Database".
Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28932 βΌ
π Read
via "National Vulnerability Database".
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.π Read
via "National Vulnerability Database".
π΄ Linux Trojan XorDdos Attacks Surge, Targeting Cloud, IoT π΄
π Read
via "Dark Reading".
Analysts have seen a massive spike in malicious activity by the XorDdos trojan in the last six months, against Linux cloud and IoT infrastructures .π Read
via "Dark Reading".
Dark Reading
Linux Trojan XorDdos Attacks Surge, Targeting Cloud, IoT
Analysts have seen a massive spike in malicious activity by the XorDdos Trojan in the last six months, against Linux cloud and IoT infrastructures .
π HHS Warns Healthcare Industry of Russian Threat Groups π
π Read
via "".
A new alert, via the HHS Cybersecurity Program, is reminding healthcare organizations about four Russian threat groups.π Read
via "".
βΌ CVE-2022-31466 βΌ
π Read
via "National Vulnerability Database".
Quick Heal Total Security before 12.1.1.27 has a TOCTOU race condition that leads to privilege escalation. It may follow a symlink that was created after a malware check.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28944 βΌ
π Read
via "National Vulnerability Database".
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ΓΒΆΓΒΆ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32935 βΌ
π Read
via "National Vulnerability Database".
The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.π Read
via "National Vulnerability Database".
βΌ CVE-2021-42233 βΌ
π Read
via "National Vulnerability Database".
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32941 βΌ
π Read
via "National Vulnerability Database".
Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).π Read
via "National Vulnerability Database".
βΌ CVE-2022-31467 βΌ
π Read
via "National Vulnerability Database".
Quick Heal Total Security before 12.1.1.27 allows DLL hijacking during installation.π Read
via "National Vulnerability Database".
π΄ Malicious Python Repository Package Drops Cobalt Strike on Windows, macOS & Linux Systems π΄
π Read
via "Dark Reading".
The PyPI "pymafka" package is the latest example of growing attacker interest in abusing widely used open source software repositories.π Read
via "Dark Reading".
Dark Reading
Malicious Python Repository Package Drops Cobalt Strike on Windows, macOS & Linux Systems
The PyPI "pymafka" package is the latest example of growing attacker interest in abusing widely used open source software repositories.
π΄ Multiple Governments Buying Android Zero-Days for Spying: Google π΄
π Read
via "Dark Reading".
An analysis from Google TAG shows that Android zero-day exploits were packaged and sold for state-backed surveillance.π Read
via "Dark Reading".
Dark Reading
Multiple Governments Buying Android Zero-Days for Spying: Google
An analysis from Google TAG shows that Android zero-day exploits were packaged and sold for state-backed surveillance.