πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacks πŸ—“οΈ

Reflected XSS and DOM-based XSS bugs net researchers $3,000 and $5,000 bug bounties

πŸ“– Read

via "The Daily Swig".
πŸ›  Faraday 4.0.4 πŸ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

πŸ“– Read

via "Packet Storm Security".
❌ Malicious Npm Packages Tapped Again to Target Discord Users ❌

Recent LofyLife campaign steals tokens and infects client files to monitor various user actions, such as log-ins, password changes and payment methods.

πŸ“– Read

via "Threat Post".
πŸ•΄ Malicious npm Packages Scarf Up Discord Tokens, Credit Card Info πŸ•΄

The campaign uses four malicious packages to spread "Volt Stealer" and "Lofy Stealer" malware in the open source npm software package repository.

πŸ“– Read

via "Dark Reading".
⚠ How to celebrate SysAdmin Day! ⚠

I've just popped in to wish you all/The best SysAdmin Day!

πŸ“– Read

via "Naked Security".
πŸ—“οΈ GitHub Actions workflow flaws provided write access to projects including Logstash πŸ—“οΈ

Malicious builds and wider infrastructural compromise were worst-case scenarios

πŸ“– Read

via "The Daily Swig".
πŸ” Friday Five 7/29 πŸ”

Read about new findings from IBM's most recent Cost of a Data Breach Report, a data breach that could affect over 5 million Twitter users, the latest cybersecurity legislation making its way through Congress, and more all in this week's Friday Five!


πŸ“– Read

via "".
β€Ό CVE-2022-2576 β€Ό

In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRequest. Especially, if used with certificate based cipher suites, that results in message amplification (DDoS other peers) and high CPU load (DoS own peer). The misbehavior occurs only with DTLS_VERIFY_PEERS_ON_RESUMPTION_THRESHOLD values larger than 0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35643 β€Ό

IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36123 β€Ό

The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Big Questions Remain Around Massive Shanghai Police Data Breach πŸ•΄

Why was PII belonging to nearly 1 billion people housed in a single, open database? Why didn't anyone notice it was downloaded?

πŸ“– Read

via "Dark Reading".
πŸ‘2
πŸ•΄ Amazon Adds Malware Detection to GuardDuty TDR Service πŸ•΄

The new GuardDuty Malware Protection and Amazon Detective were among 10 products and services unveiled at AWS re:Inforce in Boston this week.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-35632 β€Ό

The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). This issue was resolved in Velociraptor 0.6.5-2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2016-4981 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4982. Reason: This candidate is a duplicate of CVE-2016-4982. Notes: All CVE users should reference CVE-2016-4982 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-2577 β€Ό

A vulnerability classified as critical was found in SourceCodester Garage Management System 1.0. This vulnerability affects unknown code of the file /edituser.php. The manipulation of the argument id with the input -2'%20UNION%20select%2011,user(),333,444--+ leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2579 β€Ό

A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument userName with the input lala<img src="" onerror=alert(1)> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27873 β€Ό

An attacker can force the victimÒ€ℒs device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360Ò€ℒs document parser. The vulnerability exists in the applicationÒ€ℒs Γ’β‚¬ΛœInsert SVGÒ€ℒ procedure. An attacker can also leverage this vulnerability to obtain victimÒ€ℒs public IP and possibly other sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35630 β€Ό

A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static HTML file. This issue was resolved in Velociraptor 0.6.5-2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2578 β€Ό

A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This issue affects some unknown processing of the file /php_action/createUser.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35631 β€Ό

On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33881 β€Ό

Parsing a maliciously crafted PRT file can force Autodesk AutoCAD 2023 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".