πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1808 β€Ό

Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31015 β€Ό

Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate early due to a thread closing a socket while the main thread is about to call select(). This will lead to the main thread raising an exception that is not handled and then causing the entire application to be killed. This issue has been fixed in Waitress 2.1.2 by no longer allowing the WSGI thread to close the socket. Instead, that is always delegated to the main thread. There is no work-around for this issue. However, users using waitress behind a reverse proxy server are less likely to have issues if the reverse proxy always reads the full response.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1893 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository polonel/trudesk prior to 1.2.3.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-1947 β€Ό

Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1285 β€Ό

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft Releases Workaround for β€˜One-Click’ 0Day Under Active Attack ❌

Threat actors already are exploiting vulnerability, dubbed β€˜Follina’ and originally identified back in April, to target organizations in Russia and Tibet, researchers said.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-29875 β€Ό

A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Now (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Open Pro (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Sim (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Top (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Up (All versions < VA30 SP5 or VA40 SP2), Symbia E/S (All VB22 versions < VB22A-UD03), Symbia Evo (All VB22 versions < VB22A-UD03), Symbia Intevo (All VB22 versions < VB22A-UD03), Symbia T (All VB22 versions < VB22A-UD03), Symbia.net (All VB22 versions < VB22A-UD03), syngo.via VB10 (All versions), syngo.via VB20 (All versions), syngo.via VB30 (All versions), syngo.via VB40 (All versions < VB40B HF06), syngo.via VB50 (All versions), syngo.via VB60 (All versions < VB60B HF02). The application deserialises untrusted data without sufficient validations that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system if ports 32912/tcp or 32914/tcp are reachable.

πŸ“– Read

via "National Vulnerability Database".
⚠ Mysterious β€œFollina” zero-day hole in Office – here’s what to do! ⚠

News has emerged of a "feature" in Office that has been abused as a zero-day bug to run evil code. Turning off macros doesn't help!

πŸ“– Read

via "Naked Security".
πŸ•΄ Distinguishing AI Hype From Reality in SecOps πŸ•΄

AI and ML are important SecOps tools, but human involvement is still required.

πŸ“– Read

via "Dark Reading".
⚠ Firefox 101 is out, this time with no 0-day scares (but update anyway!) ⚠

After an intriguing month of Firefox releases, here's one with a bit less drama, probably to the collective relief of Mozilla's coders.

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Horde Webmail contains zero-day RCE bug with no patch on the horizon πŸ—“οΈ

CSRF exploit requires user to open malicious email

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2020-26184 β€Ό

Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-29098 β€Ό

Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26185 β€Ό

Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ US export ban on hacking tools tweaked after public consultation πŸ—“οΈ

Government has sought to allay misgivings of cybersecurity industry

πŸ“– Read

via "The Daily Swig".
πŸ•΄ StorCentric Launches Nexsan EZ-NAS -Network-Attached Storage for SMBs and Enterprise Edge Deployments πŸ•΄

EZ-NAS also provides add-on data backup, cloud connector and ransomware anomaly detection.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Security at the Edge: Why It's Complicated πŸ•΄

Edge technology widens the attack surface by bringing data analysis closer to where it's collected. Now is the time for public and private sector groups to establish guidelines and identify security best-practices frameworks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zero Trust Research Reveals Nearly Half of All Security Leaders Do Not Believe They Will Be Breached Despite Increasing Attacks and Adoption of Zero Trust Strategies πŸ•΄

Industry-first report finds zero trust segmentation eliminates 5 cyber disasters per year and saves $20+ million annually.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Enhanced Threat Intelligence Portal Provides Consolidated Access to Kaspersky Threat Intelligence Expertise πŸ•΄

.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Help Organizations to Mitigate Risk in Microsoft 365 with 'Vectra Protect' πŸ•΄

Vectra offers a free of charge security assessment for your cloud tenant.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ordr Secures $40 Million in Series C Funding to Answer Increased Demand for Connected Device Security πŸ•΄

Rising threat of data breaches and ransomware attacks drives need for complete and accurate real-time information about devices and their risks.

πŸ“– Read

via "Dark Reading".