πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-22453 β€Ό

IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ DHS Review Board Deems Log4j an 'Endemic' Cyber Threat πŸ•΄

Vulnerability will remain a "significant" threat for years to come and highlighted the need for more public and private sector support for open source software ecosystem, Cyber Safety Review Board says.

πŸ“– Read

via "Dark Reading".
πŸ•΄ New Phishing Kit Hijacks WordPress Sites for PayPal Scam πŸ•΄

Attackers use scam security checks to steal victims' government documents, photos, banking information, and email passwords, researchers warn.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Bishop Fox Secures $75 Million in Growth Funding From Carrick Capital Partners πŸ•΄

Offensive security leader continues to defy market and economic trends with record growth and recognized innovation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-32415 β€Ό

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34093 β€Ό

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via access_token.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34092 β€Ό

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via svg2img.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32417 β€Ό

PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32425 β€Ό

The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32416 β€Ό

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32409 β€Ό

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34094 β€Ό

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via request_token.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘2
β€Ό CVE-2022-2419 β€Ό

A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1881 β€Ό

In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2420 β€Ό

A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29890 β€Ό

In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2418 β€Ό

A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 7/15 πŸ”

This week saw the conviction of a former CIA engineer, a brief takedown of Congress.gov, and news of a promising decline in ransomware. Read about all of this and more in this week's Friday Five!


πŸ“– Read

via "".
πŸ—“οΈ Crunch time for EU web authentication plan as Mozilla launches campaign to protect status quo πŸ—“οΈ

Mozilla’s message to MEPs appears to be gaining traction, says senior public policy manager at the non-profit

πŸ“– Read

via "The Daily Swig".
πŸ•΄ How Hackers Create Fake Personas for Social Engineering πŸ•΄

And some ways to up your game for identifying fabricated online profiles of people who don't exist.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Fantasy Premier League football app introduces 2FA to tackle account takeover hacks πŸ—“οΈ

Authentication controls added to defend against account hijack threat

πŸ“– Read

via "The Daily Swig".
❀1