πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-2252 β€Ό

Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30192 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-33638, CVE-2022-33639.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Global Socket 1.4.36 πŸ› 

Global Socket is a tool for moving data from here to there, securely, fast, and through NAT and firewalls. It uses the Global Socket Relay Network to connect TCP pipes, has end-to-end encryption (using OpenSSL's SRP / RFC-5054), AES-256 and key exchange using 4096-bit Prime, requires no PKI, has Perfect Forward Secrecy, and TOR support.

πŸ“– Read

via "Packet Storm Security".
❌ Leaky Access Tokens Exposed Amazon Photos of Users ❌

Hackers with Amazon users’ authentication tokens could’ve stolen or encrypted personal photos and documents.

πŸ“– Read

via "Threat Post".
πŸ‘1
β€Ό CVE-2022-30467 β€Ό

Joy ebike Wolf Manufacturing year 2022 is vulnerable to Denial of service, which allows remote attackers to jam the key fob request via RF.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40597 β€Ό

The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ FCC commissioner urges Apple and Google to remove TikTok from app stores πŸ“’

This comes after it emerged that TikTok’s owners in Beijing have repeatedly accessed sensitive data collected from US citizens

πŸ“– Read

via "ITPro".
πŸ“’ Former Uber security chief to face fraud charges over hack coverup πŸ“’

This is thought to be the first instance of a corporate information security officer criminally charged with concealing a hack

πŸ“– Read

via "ITPro".
πŸ“’ Atos to advance NATO’s cybersecurity systems πŸ“’

The deal covers 22 Nato bases and β€Œupgrades to two key cybersecurity systems

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ Cyber security holds top spot in IT audit risk list πŸ“’

Privacy, data, and regulatory compliance are among other concerns facing IT audit departments

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-34835 β€Ό

In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Chromium browsers vulnerable to dangling markup injection πŸ—“οΈ

Fixed bug could allow attackers to extract sensitive information

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2017-20121 β€Ό

A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Database Management. The manipulation leads to improper privilege management. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20122 β€Ό

A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on onerror="$(Ò€ℒp').text(Ò€ℒHackedÒ€ℒ)" /> leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26135 β€Ό

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20123 β€Ό

A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.8 is able to address this issue. It is recommended to upgrade the affected component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20125 β€Ό

A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20124 β€Ό

A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
⚠ Firefox 102 fixes address bar spoofing security hole (and helps with Follina!) ⚠

Firefox squashes a bug that helped phishers, and brings its own helping hand to Microsoft's "Follina" saga.

πŸ“– Read

via "Naked Security".
❌ A Guide to Surviving a Ransomware Attack ❌

Oliver Tavakoli, CTO at Vectra AI, gives us hope that surviving a ransomware attack is possible, so long as we apply preparation and intentionality to our defense posture.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-40643 β€Ό

EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by default/usr/sbin/sendmail) it is possible to execute any command, which will be executed when we make a test of the configuration ("send test mail").

πŸ“– Read

via "National Vulnerability Database".