πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Ransomware and Phishing Remain IT's Biggest Concerns πŸ•΄

Security teams β€” who are already fighting off malware challenges β€” are also facing renewed attacks on cloud assets and remote systems.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-25856 β€Ό

The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as ...

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31873 β€Ό

Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31875 β€Ό

Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/scheprofile.cgi

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25871 β€Ό

All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of [CVE-2020-7600](https://security.snyk.io/vuln/SNYK-JS-QUERYMEN-559867).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25872 β€Ό

All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31874 β€Ό

ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25852 β€Ό

All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25345 β€Ό

All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31876 β€Ό

netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21213 β€Ό

This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22138 β€Ό

All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21503 β€Ό

Vulnerability in the Oracle Cloud Infrastructure product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to Oracle Cloud Infrastructure accessible data. All affected customers were notified of CVE-2022-21503 by Oracle. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33981 β€Ό

drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free flaw after deallocating raw_cmd in the raw_cmd_ioctl function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46822 β€Ό

The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46823 β€Ό

python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33987 β€Ό

The got package before 12.1.0 for Node.js allows a redirect to a UNIX socket.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Mozilla adds 'Total Cookie Protection' to its browser πŸ“’

The new function will separate cookies into a "cookie jar" and prevent user tracking

πŸ“– Read

via "ITPro".
πŸ“’ Businesses need to be more aggressive with their cyber security, Cisco warns πŸ“’

Government warnings of Ukraine-Russia cyber war spillover must be heeded in order to stay safe

πŸ“– Read

via "ITPro".
πŸ“’ IT Pro News In Review: UK 4 day week, ransomware payment rise, IBM cut ties with Russia πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft silent patches called β€œa grossly irresponsible policy” πŸ“’

Cyber security company Tenable said that the tech giant is putting customers at risk after it found two bugs in Microsoft Azure analytics software, one of which users weren’t made aware of

πŸ“– Read

via "ITPro".