πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-33638 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30192, CVE-2022-33639.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20116 β€Ό

A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown function of the file /admin/group/list/. The manipulation of the argument checked_group_id leads to basic cross site scripting (Reflected). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39074 β€Ό

IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20118 β€Ό

A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The manipulation of the argument domxss leads to basic cross site scripting (DOM). The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33639 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30192, CVE-2022-33638.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20113 β€Ό

A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20120 β€Ό

A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20117 β€Ό

A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20115 β€Ό

A vulnerability was found in TrueConf Server 4.3.7 and classified as problematic. This issue affects some unknown processing of the file /admin/conferences/list/. The manipulation of the argument sort leads to basic cross site scripting (Reflected). The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20114 β€Ό

A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknown code of the file /admin/conferences/get-all-status/. The manipulation of the argument keys[] leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2252 β€Ό

Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30192 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-33638, CVE-2022-33639.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Global Socket 1.4.36 πŸ› 

Global Socket is a tool for moving data from here to there, securely, fast, and through NAT and firewalls. It uses the Global Socket Relay Network to connect TCP pipes, has end-to-end encryption (using OpenSSL's SRP / RFC-5054), AES-256 and key exchange using 4096-bit Prime, requires no PKI, has Perfect Forward Secrecy, and TOR support.

πŸ“– Read

via "Packet Storm Security".
❌ Leaky Access Tokens Exposed Amazon Photos of Users ❌

Hackers with Amazon users’ authentication tokens could’ve stolen or encrypted personal photos and documents.

πŸ“– Read

via "Threat Post".
πŸ‘1
β€Ό CVE-2022-30467 β€Ό

Joy ebike Wolf Manufacturing year 2022 is vulnerable to Denial of service, which allows remote attackers to jam the key fob request via RF.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40597 β€Ό

The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ FCC commissioner urges Apple and Google to remove TikTok from app stores πŸ“’

This comes after it emerged that TikTok’s owners in Beijing have repeatedly accessed sensitive data collected from US citizens

πŸ“– Read

via "ITPro".
πŸ“’ Former Uber security chief to face fraud charges over hack coverup πŸ“’

This is thought to be the first instance of a corporate information security officer criminally charged with concealing a hack

πŸ“– Read

via "ITPro".
πŸ“’ Atos to advance NATO’s cybersecurity systems πŸ“’

The deal covers 22 Nato bases and β€Œupgrades to two key cybersecurity systems

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ Cyber security holds top spot in IT audit risk list πŸ“’

Privacy, data, and regulatory compliance are among other concerns facing IT audit departments

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-34835 β€Ό

In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.

πŸ“– Read

via "National Vulnerability Database".