πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1720 β€Ό

Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31794 β€Ό

An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  TOR Virtual Network Tunneling Tool 0.4.7.8 πŸ› 

Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs). This is the source code release.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Credential Sharing as a Service: The Hidden Risk of Low-Code/No-Code πŸ•΄

Low-code/no-code platforms allow users to embed their existing user identities within an application, increasing the risk of credentials leakage.

πŸ“– Read

via "Dark Reading".
πŸ•΄ DDoS Attacks Delay Putin Speech at Russian Economic Forum πŸ•΄

A Kremlin spokesman said that the St. Petersburg International Economic Forum accreditation and admissions systems were shut down by a DDoS attack.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Name That Toon: Cuter Than a June Bug πŸ•΄

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Why Paper Receipts are Money at the Drive-Thru β™ŸοΈ

Check out the handmade sign posted to the front door of a shuttered Jimmy John's sandwich chain shop in Missouri last week. See if you can tell from the store owner's message what happened.

πŸ“– Read

via "Krebs on Security".
⚠ Interpol busts 2000 suspects in phone scamming takedown ⚠

Friends don't let friends get scammed. Not everyone knows how typical scams unfold, so here are some real-world examples...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-22318 β€Ό

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33913 β€Ό

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22414 β€Ό

IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2128 β€Ό

Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32983 β€Ό

Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22317 β€Ό

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Feds Take Down Russian 'RSOCKS' Botnet πŸ•΄

RSOCKS commandeered millions of devices in order to offer proxy services used to mask malicious traffic.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Capital One Attacker Exploited Misconfigured AWS Databases πŸ•΄

After bragging in underground forums, the woman who stole 100 million credit applications from Capital One has been found guilty.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2017-20065 β€Ό

A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20066 β€Ό

A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31062 β€Ό

### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20074 β€Ό

A vulnerability was found in Hindu Matrimonial Script and classified as critical. Affected by this issue is some unknown functionality of the file /admin/newsletter1.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20079 β€Ό

A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unknown functionality of the file /admin/photo.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".