πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-0722 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40897 β€Ό

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2217 β€Ό

Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 7.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40895 β€Ό

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40899 β€Ό

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40896 β€Ό

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40898 β€Ό

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying crafted invalid files.

πŸ“– Read

via "National Vulnerability Database".
πŸ” What is Intellectual Property? Understanding IP Rights, Negligence, Infringement & More πŸ”

What is intellectual property? We define the term and explain how IP negligence and infringement can harm your organization.

πŸ“– Read

via "".
πŸ—“οΈ Oracle patches β€˜miracle exploit’ impacting Middleware Fusion, cloud services πŸ—“οΈ

Researchers describe discovery of β€˜mega’ zero-day

πŸ“– Read

via "The Daily Swig".
πŸ•΄ It's a Race to Secure the Software Supply Chain β€” Have You Already Stumbled? πŸ•΄

If you haven't properly addressed the issue, you're already behind. But even if you've had a false start, it's never too late to get back up.

πŸ“– Read

via "Dark Reading".
⚠ OpenSSL issues a bugfix for the previous bugfix ⚠

Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-40900 β€Ό

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40901 β€Ό

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2218 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository ionicabizau/parse-url prior to 7.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2216 β€Ό

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2208 β€Ό

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2207 β€Ό

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Thrive Acquires DSM πŸ•΄

DSM is now the third acquisition by Thrive in Florida in the past six months.

πŸ“– Read

via "Dark Reading".
⚠ FTC warns of LGBTQ+ extortion scams – be aware before you share! ⚠

It's a simple jingle and it's solid advice: "If in doubt, don't give it out!"

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Untrusted types: Researcher demos trick to beat Trusted Types protection in Google Chrome πŸ—“οΈ

Flaws in protection mechanism leaves websites more exposed to DOM XSS-based attacks

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2017-20101 β€Ό

A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely.

πŸ“– Read

via "National Vulnerability Database".