πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-34907 β€Ό

An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34906 β€Ό

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35131 β€Ό

Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36375 β€Ό

Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2020-36290 β€Ό

The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22686 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Cloud fax company claims healthcare pros are ditching email for β€˜more secure’ fax πŸ—“οΈ

The fax is dead. Long live the online fax? A new study suggests many healthcare professionals believe that flaws in today’s web security landscape are prompting a return to what’s been deemed an β€œextr

πŸ“– Read

via "The Daily Swig".
❌ IoT Botnets Fuels DDoS Attacks – Are You Prepared? ❌

The increased proliferation of IoT devices paved the way for the rise of IoT botnets that amplifies DDoS attacks today. This is a dangerous warning that the possibility of a sophisticated DDoS attack and a prolonged service outage will prevent businesses from growing.

πŸ“– Read

via "Threat Post".
❌ Phishing Attacks Skyrocket with Microsoft and Facebook as Most Abused Brands ❌

Instances of phishing attacks leveraging the Microsoft brand increased 266 percent in Q1 compared to the year prior.

πŸ“– Read

via "Threat Post".
πŸ‘1
πŸ—“οΈ Critical security vulnerability in Grails could lead to remote code execution πŸ—“οΈ

Maintainers warn to patch all versions of open source web app framework – even those not deemed vulnerable

πŸ“– Read

via "The Daily Swig".
πŸ•΄ The Beautiful Lies of Machine Learning in Security πŸ•΄

Machine learning should be considered an extension of β€” not a replacement for β€” existing security methods, systems, and teams.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Siemens Energy Takes Next Step to Protect Critical Infrastructure πŸ•΄

Company joins AWS Partner Network to provide customers with industrial cybersecurity solution to ensure reliable electricity and fuel supplies.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-33457 β€Ό

An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmac_params() in modules/preprocs/nasm/nasm-pp.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33745 β€Ό

insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33460 β€Ό

An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in if_condition() in modules/preprocs/nasm/nasm-pp.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33451 β€Ό

An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33440 β€Ό

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_commit() in mjs.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36161 β€Ό

Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33461 β€Ό

An issue was discovered in yasm version 1.3.0. There is a use-after-free in yasm_intnum_destroy() in libyasm/intnum.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33464 β€Ό

An issue was discovered in yasm version 1.3.0. There is a heap-buffer-overflow in inc_fopen() in modules/preprocs/nasm/nasm-pp.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33467 β€Ό

An issue was discovered in yasm version 1.3.0. There is a use-after-free in pp_getline() in modules/preprocs/nasm/nasm-pp.c.

πŸ“– Read

via "National Vulnerability Database".