πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ HackerOne employee stole data from bug bounty reports for financial gain πŸ—“οΈ

Vulnerability disclosure platform shares details of incident

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Name That Edge Toon: On Guard πŸ•΄

Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-33744 β€Ό

Arm guests can cause Dom0 DoS via PV devices When mapping pages of guests on Arm, dom0 is using an rbtree to keep track of the foreign mappings. Updating of that rbtree is not always done completely with the related lock held, resulting in a small race window, which can be used by unprivileged guests via PV devices to cause inconsistencies of the rbtree. These inconsistencies can lead to Denial of Service (DoS) of dom0, e.g. by causing crashes or the inability to perform further mappings of other guests' memory pages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33743 β€Ό

network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code label was moved in a way allowing for SKBs having references (pointers) retained for further processing to nevertheless be freed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43702 β€Ό

ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26365 β€Ό

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33742 β€Ό

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30289 β€Ό

A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2.4. An attacker can abuse the vulnerability to upload a malicious file that will then be executed by a victim when they open the file location.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33740 β€Ό

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33741 β€Ό

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30290 β€Ό

In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker can abuse the identified vulnerability in order to arbitrarily change their registered e-mail address as well as their API key, even though such action is not possible through the interface, legitimately.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2304 β€Ό

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 3 Cyber Threats Resulting From Today's Technology Choices to Hit Businesses by 2024 πŸ•΄

Companies need to consider the cost to disengage from the cloud along with proactive risk management that looks at governance issues resulting from heavy use of low- and no-code tools.

πŸ“– Read

via "Dark Reading".
⚠ Canadian cybercriminal pleads guilty to β€œNetWalker” attacks in US ⚠

Bust in Canada, now bust in the USA as well.

πŸ“– Read

via "Naked Security".
πŸ›  OpenSSL Toolkit 1.1.1q πŸ› 

OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols with full-strength cryptography world-wide.

πŸ“– Read

via "Packet Storm Security".
πŸ›  C Language Reverse Shell Generator πŸ› 

This is a C language reverse shell generator that is written in Python.

πŸ“– Read

via "Packet Storm Security".
πŸ›  OpenSSL Toolkit 3.0.5 πŸ› 

OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols with full-strength cryptography world-wide. The 3.x series is the current major version of OpenSSL.

πŸ“– Read

via "Packet Storm Security".
πŸ›  TripleCross Linux eBPF Rootkit πŸ› 

TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology. TripleCross is inspired by previous implant designs in this area, notably the works of Jeff Dileo at DEFCON 271, Pat Hogan at DEFCON 292, Guillaume Fournier and Sylvain Afchain also at DEFCON 293, and Kris NΓ³va's Boopkit4. The authors reuse and extend some of the techniques pioneered by these previous explorations of the offensive capabilities of eBPF technology.

πŸ“– Read

via "Packet Storm Security".
πŸ—“οΈ CWE Top 25: These are the most dangerous software weaknesses of 2022 πŸ—“οΈ

CISA and MITRE’s latest CWE shakeup reveals the most severe threats impacting enterprise software today

πŸ“– Read

via "The Daily Swig".
⚠ Google patches β€œin-the-wild” Chrome zero-day – update now! ⚠

Running Chrome? Do the "Help-About-Update" dance move right now, just to be sure...

πŸ“– Read

via "Naked Security".
πŸ‘1
πŸ—“οΈ Spring Data MongoDB hit by another critical SpEL injection flaw πŸ—“οΈ

Bug mirrors recent SpEL injection vulnerability that emerged alongside β€˜SpringShell’ issue

πŸ“– Read

via "The Daily Swig".