πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-29376 β€Ό

Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32958 β€Ό

Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to gain the secret key, subsequently allowing them to generate valid session tokens for the web user interface (UI). With access to the web UI an attacker can access assets managed by the SRA installation and could compromise the installation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30015 β€Ό

In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored xss.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-31263 β€Ό

app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29305 β€Ό

imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29377 β€Ό

Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0734 β€Ό

A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29309 β€Ό

mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0910 β€Ό

A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through 5.21, that could allow an authenticated attacker to bypass the second authentication phase to connect the IPsec VPN server even though the two-factor authentication (2FA) was enabled.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ SES GS wins US government’s TROJAN contract πŸ“’

The five-year deal is aimed at fortifying the country’s cyber security resilience

πŸ“– Read

via "ITPro".
πŸ“’ What is data and big data mining? An easy guide πŸ“’

You have a lot of data, but how do you find the right data to make a business decision?

πŸ“– Read

via "ITPro".
πŸ“’ Ethical hackers handed lifeline in controversial US cyber crime review πŸ“’

The DoJ's latest ruling is a boon to "good-faith security research" but some argue that white hats are still not protected

πŸ“– Read

via "ITPro".
πŸ“’ Ministry of Defence pledges resilience to all known vulnerabilities and cyber attack methods by 2030 πŸ“’

New MoD cyber security strategy is underpinned by a 'secure by design' approach that will run across the organisation

πŸ“– Read

via "ITPro".
πŸ“’ Ransomware group Conti threatens to overthrow Costa Rican government πŸ“’

It has urged citizens to go out onto the streets to demand their government pays the ransomware demand

πŸ“– Read

via "ITPro".
πŸ“’ US security agency issues emergency alert over vulnerable VMware products πŸ“’

A string of actively exploited critical vulnerabilities across five popular VMware products has been described as an "unacceptable risk" to government systems

πŸ“– Read

via "ITPro".
πŸ“’ IT admin deletes company’s databases and is jailed for seven years πŸ“’

Forensic experts correlated WiFi connectivity logs and timestamps with internal CCTV footage to confirm their suspicions

πŸ“– Read

via "ITPro".
πŸ“’ Researchers demonstrate how to install malware on iPhone after it's switched off πŸ“’

The most recent iPhones are found to be vulnerable after researchers discover an exploit in a beloved iOS 15 feature

πŸ“– Read

via "ITPro".
πŸ“’ Palo Alto and Deloitte to deliver managed security services in the US πŸ“’

Freshly expanded strategic partnership will deliver threat protection, 5G security, and enable the Zero Trust Enterprise for US businesses

πŸ“– Read

via "ITPro".
πŸ“’ (ISC)2 launches free scheme to get 100,000 UK citizens into cyber security πŸ“’

The certification non-profit estimates the UK has around 33,000 cyber security vacancies, with that figure set to rise this year

πŸ“– Read

via "ITPro".
πŸ“’ The cookie phase-out might precede an AdTech apocalypse πŸ“’

With the industry phasing out third-party cookies, what does this mean for businesses reliant on them to track and improve their campaigns?

πŸ“– Read

via "ITPro".
πŸ“’ What is cyber warfare? πŸ“’

We explain what cyber warfare is and why you need to pay attention to the threats posed

πŸ“– Read

via "ITPro".