🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2017-20088

A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.

📖 Read

via "National Vulnerability Database".
CVE-2017-20091

A vulnerability was found in File Manager Plugin 3.0.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely.

📖 Read

via "National Vulnerability Database".
CVE-2017-20086

A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.

📖 Read

via "National Vulnerability Database".
S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast]

Latest epsiode - listen now!

📖 Read

via "Naked Security".
🗓️ Splunk patches critical vulnerability while users push for legacy updates 🗓️

Users call for security update back-port to support earlier versions

📖 Read

via "The Daily Swig".
👎1
CVE-2022-34305

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.

📖 Read

via "National Vulnerability Database".
Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug

The APT is pairing a known Microsoft flaw with a malicious document to load malware that nabs credentials from Chrome, Firefox and Edge browsers.

📖 Read

via "Threat Post".
1
🕴 How APTs Are Achieving Persistence Through IoT, OT, and Network Devices 🕴

To prevent these attacks, businesses must have complete visibility into, and access and management over, disparate devices.

📖 Read

via "Dark Reading".
🗓️ Statutory defense for ethical hacking under UK Computer Misuse Act tabled 🗓️

Amendment applies to bill related to 5G rollout and connected products

📖 Read

via "The Daily Swig".
CVE-2022-2175

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

📖 Read

via "National Vulnerability Database".
🕴 Palo Alto Networks Bolsters Its Cloud Native Security Offerings With Out-of-Band WAAS 🕴

Latest Prisma Cloud platform updates help organizations continuously monitor and secure web applications with maximum flexibility.

📖 Read

via "Dark Reading".
🕴 Reinventing How Farming Equipment Is Remotely Controlled and Tracked 🕴

Farmers are incorporating high-tech solutions like IoT and drones to address new challenges facing agriculture.

📖 Read

via "Dark Reading".
🕴 Cyberattackers Abuse QuickBooks Cloud Service in 'Double-Spear' Campaign 🕴

Malicious invoices coming from the accounting software's legitimate domain are used to harvest phone numbers and carry out fraudulent credit-card transactions.

📖 Read

via "Dark Reading".
🕴 The Rise, Fall, and Rebirth of the Presumption of Compromise 🕴

The concept might make us sharp and realistic, but it's not enough on its own.

📖 Read

via "Dark Reading".
🕴 Pair of Brand-New Cybersecurity Bills Become Law 🕴

Bipartisan legislation allows cybersecurity experts to work across multiple agencies and provides federal support for local governments.

📖 Read

via "Dark Reading".
🕴 ShiftLeft: Focus On 'Attackability' To Better Prioritize Vulnerabilities 🕴

ShiftLeft's Manesh Gupta join Dark Reading's Terry Sweeney at Dark Reading News Desk during RSA Conference to talk about looking at vulnerability management through the lens of "attackability."

📖 Read

via "Dark Reading".
CVE-2022-34176

Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.

📖 Read

via "National Vulnerability Database".
CVE-2021-41432

A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.

📖 Read

via "National Vulnerability Database".
CVE-2022-32125

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job.

📖 Read

via "National Vulnerability Database".
CVE-2022-33097

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.

📖 Read

via "National Vulnerability Database".
CVE-2022-33114

Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.

📖 Read

via "National Vulnerability Database".