πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-22068 β€Ό

kernel event may contain unexpected content which is not generated by NPU software in asynchronous execution mode in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ GhostTouch: Hackers can reach your phone’s touchscreen without even touching it πŸ—“οΈ

New research shows how electromagnetic interference can be used to trigger arbitrary behavior on mobile touchscreens, although caveats apply

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Understanding and Mitigating Single Sign-on Risk πŸ•΄

SSO's one-to-many architecture is both a big advantage and a weakness.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-40678 β€Ό

In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31273 β€Ό

An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Oblivious DNS-over-HTTPS offers privacy enhancements to secure lookup protocol πŸ—“οΈ

ODoH is said to enhance user privacy without compromising performance

πŸ“– Read

via "The Daily Swig".
πŸ‘1πŸ‘Ž1
πŸ—“οΈ LenelS2 access control vulnerabilities leave door open to lock manipulation πŸ—“οΈ

Vendor addresses threat to integrity and availability of physical access systems

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Optiv MXDR Enhances Detection Coverage With Expanded Cloud Integration πŸ•΄

Service ingests AWS, GCP and Microsoft Azure data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-40660 β€Ό

An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launching a denial of service (DoS) attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32336 β€Ό

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27889 β€Ό

The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or authorization operations to fail for the duration of the attack. This could lead to performance degradation or login failures for customer Palantir Foundry environments. This vulnerability is resolved in Multipass 3.647.0. This issue affects: Palantir Foundry Multipass versions prior to 3.647.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31845 β€Ό

A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31309 β€Ό

A vulnerability in live_check.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to obtain sensitive router information via execution of the exec cmd function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31847 β€Ό

A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31846 β€Ό

A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31308 β€Ό

A vulnerability in live_mfg.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.191012 allows attackers to obtain sensitive router information via execution of the exec cmd function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31311 β€Ό

An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
⚠ You’re invited! Join us for a live walkthrough of the β€œFollina” story… ⚠

Live demo, plain English, no sales pitch, just a chance to watch an attack dissected in safety. Join us if you can!

πŸ“– Read

via "Naked Security".
πŸ” Latest Chrome Update Resolves Four High Risk Vulnerabilities πŸ”

Google has yet again updated Chrome to resolve multiple vulnerabilities in the browser, including four marked high severity.

πŸ“– Read

via "".
πŸ•΄ How Can Security Partnerships Help to Mitigate the Increasing Cyber Threat? πŸ•΄

Martyn Ryder from Morphean explains why forging trusted partnerships is integral to the future of physical security in a world of networks, systems, and the cloud.

πŸ“– Read

via "Dark Reading".
⚠ Murder suspect admits she tracked cheating partner with hidden AirTag ⚠

O! What a tangled web we weave, when first we practise to deceive.

πŸ“– Read

via "Naked Security".