πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-30526 β€Ό

A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions 4.16 through 5.30, USG20(W)-VPN firmware versions 4.16 through 5.30, ATP series firmware versions 4.32 through 5.30, VPN series firmware versions 4.30 through 5.30, USG/ZyWALL series firmware versions 4.09 through 4.72, which could allow a local attacker to execute some OS commands with root privileges in some directories on a vulnerable device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30532 β€Ό

In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2030 β€Ό

A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions 4.16 through 5.30, USG20(W)-VPN firmware versions 4.16 through 5.30, ATP series firmware versions 4.32 through 5.30, VPN series firmware versions 4.30 through 5.30, USG/ZyWALL series firmware versions 4.11 through 4.72, that could allow an authenticated attacker to access some restricted files on a vulnerable device.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ LDAP Account Manager bug poses unauthenticated remote code execution risk πŸ—“οΈ

Silence of the LAM

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-2467 β€Ό

A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username with the input 1@a.com' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2468 β€Ό

A vulnerability was found in SourceCodester Garage Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /editbrand.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Tor Browser 11.5 release enables users to automatically circumvent censorship πŸ—“οΈ

New update addresses challenges faced by users in repressive countries

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Protecting Against Kubernetes-Borne Ransomware πŸ•΄

The conventional wisdom that virtual container environments were somehow immune from malware and hackers has been upended.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Enso Security Leads Industry Mission to Bring Control to Chaos With Community-Driven AppSec Map πŸ•΄

Builds personalization, posture scoring and enhanced market intelligence into interactive map of the application security ecosystem.

πŸ“– Read

via "Dark Reading".
πŸ•΄ GhangorCloud Announces CAPE, a Next Generation Unified Compliance and Data Privacy Enforcement Solution πŸ•΄

New CAPE platform delivers patented intelligent automation and enforcement of consumer data privacy mandates at lowest total cost of ownership.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ β€˜Password extraction risk’ in identity provider Okta disputed πŸ—“οΈ

Researchers go public after vendor disputes impersonation threat

πŸ“– Read

via "The Daily Swig".
πŸ‘1
❌ FBI Warns Fake Crypto Apps are Bilking Investors of Millions ❌

Threat actors offer victims what appear to be investment services from legitimate companies to lure them into downloading malicious apps aimed at defrauding them.

πŸ“– Read

via "Threat Post".
❌ Authentication Risks Discovered in Okta Platform ❌

Four newly discovered attack paths could lead to PII exposure, account takeover, even organizational data destruction.

πŸ“– Read

via "Threat Post".
πŸ•΄ Unpatched GPS Tracker Security Bugs Threaten 1.5M Vehicles with Disruption πŸ•΄

A GPS device from MiCODUS has six security bugs that could allow attackers to monitor 1.5 million vehicles that use the tracker, or even remotely disable vehicles.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-29060 β€Ό

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2192 β€Ό

Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2453 β€Ό

Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24082 β€Ό

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26113 β€Ό

An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35405 β€Ό

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1984 β€Ό

This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated attackers to elevate privileges via a malicious serialized payload.

πŸ“– Read

via "National Vulnerability Database".