πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Microsoft Elevation-of-Privilege Vulnerabilities Spiked Again in 2021 πŸ•΄

But there was a substantial drop in the overall number of critical vulnerabilities that the company disclosed last year, new analysis shows.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-29333 β€Ό

A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 'There's No Ceiling': Ransomware's Alarming Growth Signals a New Era, Verizon DBIR Finds πŸ•΄

Ransomware has become so efficient, and the underground economy so professional, that traditional monetization of stolen data may be on its way out.

πŸ“– Read

via "Dark Reading".
⚠ Poisoned Python and PHP packages purloin passwords for AWS access ⚠

More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-29337 β€Ό

C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22497 β€Ό

IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29334 β€Ό

An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29349 β€Ό

kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29710 β€Ό

A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29358 β€Ό

epub2txt2 v2.04 was discovered to contain an integer overflow via the function bug in _parse_special_tag at sxmlc.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted XML file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29362 β€Ό

A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ParentID parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29361 β€Ό

Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29359 β€Ό

A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Malicious Python library CTX removed from PyPI repo πŸ—“οΈ

A suspicious developer appears to have performed a domain hijack to take over the original project

πŸ“– Read

via "The Daily Swig".
πŸ•΄ DBIR Makes a Case for Passwordless πŸ•΄

Verizon's "2022 Data Breach Investigations Report" repeatedly makes the point that criminals are stealing credentials to carry out their attacks.

πŸ“– Read

via "Dark Reading".
πŸ‘1
❌ Zoom Patches β€˜Zero-Click’ RCE Bug ❌

The Google Project Zero researcher found a bug in XML parsing on the Zoom client and server.

πŸ“– Read

via "Threat Post".
❌ Verizon Report: Ransomware, Human Error Among Top Security Risks ❌

2022’s DBIR also highlighted the far-reaching impact of supply-chain breaches and how organizations and their employees are the reasons why incidents occur.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Tails users warned not to launch bundled Tor Browser until security fix is released πŸ—“οΈ

Critical vulnerability has been fixed upstream, but Tails dev team β€˜doesn’t have the capacity to publish an emergency release earlier’

πŸ“– Read

via "The Daily Swig".
❌ Link Found Connecting Chaos, Onyx and Yashma Ransomware ❌

A slip-up by a malware author has allowed researchers to taxonomize three ransomware variations going by different names.

πŸ“– Read

via "Threat Post".
πŸ•΄ DDoS Extortion Attack Flagged as Possible REvil Resurgence πŸ•΄

A DDoS campaign observed by Akamai from actors claiming to be REvil would represent a major pivot in tactics for the gang.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Industry 4.0 Points Up Need for Improved Security for Manufacturers πŸ•΄

With manufacturing ranking as the fourth most targeted sector, manufacturers that understand their exposure will be able to build the necessary security maturity.

πŸ“– Read

via "Dark Reading".