πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1683 β€Ό

The amtyThumb WordPress plugin through 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement via its shortcode, leading to an SQL injection and is exploitable by any authenticated user (and not just Author+ like the original advisory mention) due to the fact that they can execute shortcodes via an AJAX action

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1421 β€Ό

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1469 β€Ό

The FiboSearch WordPress plugin before 1.17.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1689 β€Ό

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1687 β€Ό

The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it in a SQL statement via the Manage Slider Images admin page, leading to an SQL Injection

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1424 β€Ό

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1577 β€Ό

The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which contain more details. Or disable the automatic backup schedule

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1570 β€Ό

The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1422 β€Ό

The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.

πŸ“– Read

via "National Vulnerability Database".
❌ Paying Ransomware Paints Bigger Bullseye on Target’s Back ❌

Ransomware attackers often strike targets twice, regardless of whether the ransom was paid.

πŸ“– Read

via "Threat Post".
❌ Taming the Digital Asset Tsunami ❌

Rob Gurzeev, CEO and Co-Founder of CyCognito, explores external attack surface soft spots tied to an ever-expanding number of digital assets companies too often struggle to keep track of and manage effectively.

πŸ“– Read

via "Threat Post".
πŸ•΄ How Do We Secure Our Cities From Attack? πŸ•΄

Physical access matters in keeping people and buildings safe. Points to consider when establishing a physical security protocol are ways to lock down an area to keep people safe, approaches to communicate clear safety directions, and access control.

πŸ“– Read

via "Dark Reading".
⚠ Know your enemy! Learn how cybercrime adversaries get in… ⚠

Here's how 144 recent attacks actually went down in real life. Don't let this happen to you!

πŸ“– Read

via "Naked Security".
πŸ—“οΈ WWDC 2022: Apple showcases next-gen security tech at annual developer event πŸ—“οΈ

Passkeys, Safety Check, and Private Access Tokens demonstrated during week-long virtual conference

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-31497 β€Ό

LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30552 β€Ό

Das U-Boot 2022.01 has a Buffer Overflow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1996 β€Ό

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30790 β€Ό

Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.

πŸ“– Read

via "National Vulnerability Database".
⚠ SSNDOB Market servers seized, identity theft β€œbrokerage”” shut down ⚠

The online identity "brokerage" SSNDOB Market didn't want pople to be in any doubt what it was selling.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-30919 β€Ό

H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID_5G parameter at /goform/aspForm.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30913 β€Ό

H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the ipqos_set_bandwidth parameter at /goform/aspForm.

πŸ“– Read

via "National Vulnerability Database".