πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-32250 β€Ό

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26866 β€Ό

Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29085 β€Ό

Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42877 β€Ό

TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29084 β€Ό

Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29767 β€Ό

adbyby v2.7 allows external users to make connections via port 8118. This can cause a program logic error and lead to a Denial of Service (DoS) via high CPU usage due to a large number of connections.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ IT Pro News In Review: Businesses cancel cyber policies, EE milestone, Costa Rica Conti attack πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ“’ The cookie phase-out might precede an AdTech apocalypse πŸ“’

With the industry phasing out third-party cookies, what does this mean for businesses reliant on them to track and improve their campaigns?

πŸ“– Read

via "ITPro".
πŸ“’ DOE β€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œfundsβ€Œ β€Œdevelopment of Qunnect's Quantum Repeater πŸ“’

The $1.85 million grant will eventually pave the way for quantum internet

πŸ“– Read

via "ITPro".
πŸ“’ Ministry of Defence pledges resilience to all known vulnerabilities and cyber attack methods by 2030 πŸ“’

New MoD cyber security strategy is underpinned by a 'secure by design' approach that will run across the organisation

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-32271 β€Ό

In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1987 β€Ό

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32265 β€Ό

qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1988 β€Ό

Cross-site Scripting (XSS) - Generic in GitHub repository neorazorx/facturascripts prior to 2022.09.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32270 β€Ό

In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL planting could also occur).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32268 β€Ό

StarWind SAN and NAS v0.2 build 1914 allow remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32269 β€Ό

In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Second ransomware group attacks Costa Rica πŸ“’

The country’s health service has had its systems affected by the new attack

πŸ“– Read

via "ITPro".
πŸ“’ Zscaler and Siemens team up to provide all-in-one digital transformation solution πŸ“’

Zscaler-powered zero trust OT security platform is now available globally via Siemens

πŸ“– Read

via "ITPro".
πŸ“’ GitHub Enterprise Server 3.5 is equipped with a horde of new security protections πŸ“’

Admins are also given more controls to ensure the smooth running of servers, be it on-prem or in the cloud

πŸ“– Read

via "ITPro".
πŸ“’ What is your digital footprint? πŸ“’

Your digital footprint is always growing – so we explore how you can keep it under control

πŸ“– Read

via "ITPro".