πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-27616 β€Ό

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34969 β€Ό

PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34937 β€Ό

Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34967 β€Ό

The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-27620 β€Ό

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server before 2.2.3-0331 allows remote authenticated users to read arbitrary files via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 5 Ways Chess Can Inspire Strategic Cybersecurity Thinking πŸ•΄

Rising interest in chess may feed the next generation of cybersecurity experts.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ—“οΈ Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisory πŸ—“οΈ

β€˜We believe that announcing vulnerabilities without a fix is the best solution for a difficult problem’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Netskope Acquires Infiot, Will Deliver Fully Integrated, Single-Vendor SASE Platform πŸ•΄

Converged SASE platform provides AI-driven Zero trust security and simplified, optimized connectivity to any network location or device, including IoT.

πŸ“– Read

via "Dark Reading".
⚠ Cryptocoin β€œtoken swapper” Nomad loses $200 million in coding blunder ⚠

Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.

πŸ“– Read

via "Naked Security".
πŸ•΄ CompTIA CEO Outlines Initiative to Create the Pre-eminent Destination to Start, Build and β€˜Supercharge’ a Tech Career πŸ•΄

Todd Thibodeaux uses ChannelCon 2022 state of the industry remarks to unveil CompTIA’s Project Agora; invites broad industry participation in the effort to fight for tech talent.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Druva Introduces the Data Resiliency Guarantee of up to $10 Million πŸ•΄

The new program offers robust protection across all five data risk categories: cyber, human, application, operation, and environmental.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Swiss government announces upcoming launch of federal bug bounty program πŸ—“οΈ

Switzerland Bug Bounty AG awarded program management contract

πŸ“– Read

via "The Daily Swig".
❌ VMWare Urges Users to Patch Critical Authentication Bypass Bug ❌

Vulnerabilityβ€”for which a proof-of-concept is forthcomingβ€”is one of a string of flaws the company fixed that could lead to an attack chain.

πŸ“– Read

via "Threat Post".
πŸ•΄ ShiftLeft Appoints Prevention-First, Cybersecurity Visionary and AI/ML Pioneer Stuart McClure as CEO πŸ•΄

Serial entrepreneur, cybersecurity leader, and industry veteran joins ShiftLeft to drive growth and AI/ML innovation globally.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23442 β€Ό

An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs via CLI commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32293 β€Ό

In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36359 β€Ό

An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35620 β€Ό

D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35619 β€Ό

D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function ssdpcgi_main.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27484 β€Ό

A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34973 β€Ό

D-Link DIR820LA1_FW106B02 was discovered to contain a buffer overflow via the nextPage parameter at ping.ccp.

πŸ“– Read

via "National Vulnerability Database".