πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-30275 β€Ό

The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini driver configuration file. In addition, this password is used for access control to MOSCAD/STS projects protected with the Legacy Password feature. In this case, an insecure CRC of the password is present in the project file: this CRC is validated against the password in the driver configuration file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29957 β€Ό

The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP); Cold restart (18512/UDP); SIS communications (12345/TCP); and Wireless Gateway Protocol (18515/UDP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36129 β€Ό

HashiCorp Vault and Vault Enterprise through 2022-07-17 have Incorrect Access Control.

πŸ“– Read

via "National Vulnerability Database".
⚠ Mild monthly security update from Firefox – but update anyway ⚠

You're probably thinking we're going to say, "Don't delay/Do it today"... and that's exactly what we are saying!

πŸ“– Read

via "Naked Security".
β™ŸοΈ A Retrospective on the 2015 Ashley Madison Breach β™ŸοΈ

It's been seven years since the online cheating site AshleyMadison.com was hacked and highly sensitive data about its users posted online. The leak led to the public shaming and extortion of many AshleyMadison users, and to at least two suicides. To date, little is publicly known about the perpetrators or the true motivation for the attack. But a recent review of AshleyMadison mentions across Russian cybercrime forums and far-right underground websites in the months leading up to the hack revealed some previously unreported details that may deserve further scrutiny.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2022-34612 β€Ό

Rizin v0.4.0 and below was discovered to contain an integer overflow via the function get_long_object(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36880 β€Ό

The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34594 β€Ό

Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component ip/school/moudel/update_subject.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Subject text field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36879 β€Ό

An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34971 β€Ό

An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34611 β€Ό

A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Open-Xchange issues fixes for RCE, SSRF bugs in OX App Suite πŸ—“οΈ

Security release also includes precautionary patches for potential Log4j-like flaw in Logback library

πŸ“– Read

via "The Daily Swig".
πŸ‘1
πŸ” What is the OSI Model? An Overview of the OSI Model's 7 Layers πŸ”

The OSI model includes seven layers that computer systems use to communicate over networks. Learn about the OSI Model layers and how they interact in this blog.

πŸ“– Read

via "".
πŸ•΄ No More Ransom Helped More Than 1.5 Million People Decrypt Their Devices πŸ•΄

.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 8 Hot Summer Fiction Reads for Cybersecurity Pros πŸ•΄

A reading list of recommended novels curated by cybersecurity experts for cybersecurity experts.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Great BizApp Hack: Cyber-Risks in Your Everyday Business Applications πŸ•΄

IT admins can lock some of the obvious open doors in business applications, but system visibility is key. Build automatic monitoring defenses and adopt a Git-like tool so you can "version" your business apps to restore prior states.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ One in five data breaches due to software supply chain compromise, IBM report warns πŸ—“οΈ

Attack vector cost businesses 2.5% more in one year

πŸ“– Read

via "The Daily Swig".
πŸ•΄ First Cohort Graduates from PSM Cyber Stars Program at Liverpool FC πŸ•΄

New careers in IT open up for former footballers.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-36898 β€Ό

A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33970 β€Ό

Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36886 β€Ό

A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier allows attackers to create runs of an external job.

πŸ“– Read

via "National Vulnerability Database".