‼ CVE-2022-29564 ‼
📖 Read
via "National Vulnerability Database".
Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastructure, aka WND-44801.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-25361 ‼
📖 Read
via "National Vulnerability Database".
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the system. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-31495 ‼
📖 Read
via "National Vulnerability Database".
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-37589 ‼
📖 Read
via "National Vulnerability Database".
Virtua Cobranca before 12R allows SQL Injection on the login page.📖 Read
via "National Vulnerability Database".
🕴 How the C-Suite Puts Shoulders Into Zero Trust in 2022 🕴
📖 Read
via "Dark Reading".
A full 77% of tech executives say they'll increase spending in zero-trust architecture in the coming year.📖 Read
via "Dark Reading".
Dark Reading
How the C-Suite Puts Shoulders Into Zero Trust in 2022
A full 77% of tech executives say they'll increase spending in zero-trust architecture in the coming year.
🕴 RSAC Opens With Message of Transformation 🕴
📖 Read
via "Dark Reading".
Cybersecurity needs to shift its thinking ahead of the next disruption, RSA's CEO said during the opening 2022 conference keynote.📖 Read
via "Dark Reading".
Dark Reading
RSAC Opens With Message of Transformation
Cybersecurity needs to shift its thinking ahead of the next disruption, RSA's CEO said during the opening 2022 conference keynote.
‼ CVE-2022-31028 ‼
📖 Read
via "National Vulnerability Database".
MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due to HTTP clients not closing the connections. Public-facing MinIO deployments are most affected. Users should upgrade to RELEASE.2022-06-02T02-11-04Z to receive a patch. One possible workaround is to use a reverse proxy to limit the number of connections being attempted in front of MinIO, and actively rejecting connections from such malicious clients.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-31279 ‼
📖 Read
via "National Vulnerability Database".
Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution (RCE) via an unserialized pop chain in __destruct in Illuminate\Broadcasting\PendingBroadcast.php and __call in Faker\Generator.php.📖 Read
via "National Vulnerability Database".
🕴 Multilevel Extortion: DeadBolt Ransomware Targets Internet-Facing NAS Devices 🕴
📖 Read
via "Dark Reading".
The innovative ransomware targets NAS devices, has a multitiered payment and extortion scheme as well as a flexible configuration, and takes a heavily automated approach.📖 Read
via "Dark Reading".
Dark Reading
Multilevel Extortion: DeadBolt Ransomware Targets Internet-Facing NAS Devices
The innovative ransomware targets NAS devices, has a multitiered payment and extortion scheme as well as a flexible configuration, and takes a heavily automated approach.
🕴 Mandia: Keep 'Shields Up' to Survive the Current Escalation of Cyberattacks 🕴
📖 Read
via "Dark Reading".
As Mandiant CEO Kevin Mandia's company prepares to become part of Google, the incident response company continues to investigate many of the most critical cyber incidents.📖 Read
via "Dark Reading".
Dark Reading
Mandia: Keep 'Shields Up' to Survive the Current Escalation of Cyberattacks
As Mandiant CEO Kevin Mandia's company prepares to become part of Google, the incident response company continues to investigate many of the most critical cyber incidents.
‼ CVE-2020-36536 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Brandbugle. It has been rated as critical. Affected by this issue is some unknown functionality of the file /main.php. The manipulation leads to sql injection. The attack may be launched remotely.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30716 ‼
📖 Read
via "National Vulnerability Database".
Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36530 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remotely.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30717 ‼
📖 Read
via "National Vulnerability Database".
Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36531 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30725 ‼
📖 Read
via "National Vulnerability Database".
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30743 ‼
📖 Read
via "National Vulnerability Database".
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36537 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Everywhere CMS. It has been classified as critical. Affected is an unknown function. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36525 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as problematic has been found in Linking. This affects an unknown part of the component New Windows Macro. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30709 ‼
📖 Read
via "National Vulnerability Database".
Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36524 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Refined Toolkit. It has been rated as problematic. Affected by this issue is some unknown functionality of the component UI-Image/UI-Button. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.📖 Read
via "National Vulnerability Database".