πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Huntress Acquires Curricula for $22M to Disrupt Security Training Market, Elevate Cyber Readiness for SMB Employees πŸ•΄

The Curricula platform uses behavioral science with a simplified approach to train and educate users β€” and marks another step forward in Huntress’ mission to secure the 99%.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Will Your Cyber-Insurance Premiums Protect You in Times of War? πŸ•΄

Multiple cyber-insurance carriers have adopted act-of-war exclusions due to global political instability and are seeking to stretch the definition of war to deny coverage.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Okta Exposes Passwords in Clear Text for Possible Theft πŸ•΄

Researchers say Okta could allow attackers to easily exfiltrate passwords, impersonate other users, and alter logs to cover their tracks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-34001 β€Ό

Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27545 β€Ό

BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27544 β€Ό

BigFix Web Reports authorized users may see SMTP credentials in clear text.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22359 β€Ό

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22417 β€Ό

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223127.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22358 β€Ό

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 220651.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34023 β€Ό

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22360 β€Ό

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 220782.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22416 β€Ό

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 223126.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35912 β€Ό

In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2469 β€Ό

GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27580 β€Ό

A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user when opened or imported by the Safety Designer. This compromises confidentiality integrity and availability. For the attack to succeed a user must manually open a malicious project file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27579 β€Ό

A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user when opened or imported by the Flexi Soft Designer. This compromises confidentiality integrity and availability. For the attack to succeed a user must manually open a malicious project file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Startup Aims to Secure AI, Machine Learning Development πŸ•΄

With security experts warning against attacks on machine learning models and data, startup HiddenLayer aims to protect the neural networks powering AI-augmented products.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Post-Breakup, Conti Ransomware Members Remain Dangerous πŸ•΄

The gang's members have moved into different criminal activities, and could regroup once law-enforcement attention has simmered down a bit, researchers say.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-34024 β€Ό

Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34169 β€Ό

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. The Apache Xalan Java project is dormant and in the process of being retired. No future releases of Apache Xalan Java to address this issue are expected. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36305 β€Ό

Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.

πŸ“– Read

via "National Vulnerability Database".