πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-38161 β€Ό

The Gumstix Overo SBC on the VSKS board through 2022-08-09, as used on the Orlan-10 and other platforms, allows unrestricted remapping of the NOR flash memory containing the bitstream for the FPGA.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38150 β€Ό

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38155 β€Ό

TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE kernel crash.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Black Hat USA: Log4j de-obfuscator Ox4Shell β€˜dramatically’ reduces analysis time πŸ—“οΈ

Open source utility exposes payloads without running vulnerable Java code

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-2751 β€Ό

A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-206024.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-2746 β€Ό

A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. This vulnerability affects unknown code of the file Admin_ add.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-206014 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2740 β€Ό

A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated remotely. VDB-205882 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-2749 β€Ό

A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mygym/admin/index.php?view_exercises. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206017 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2750 β€Ό

A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-206022 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2744 β€Ό

A vulnerability, which was classified as critical, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality of the file /admin/add_exercises.php of the component Background Management. The manipulation of the argument exer_img leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-206012.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2747 β€Ό

A vulnerability was found in SourceCodester Simple Online Book Store and classified as critical. This issue affects some unknown processing of the file book.php. The manipulation of the argument book_isbn leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-206015.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2748 β€Ό

A vulnerability was found in SourceCodester Simple Online Book Store System. It has been classified as problematic. Affected is an unknown function of the file /admin/edit.php. The manipulation of the argument eid leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-206016.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2736 β€Ό

A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-205881 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2745 β€Ό

A vulnerability, which was classified as critical, was found in SourceCodester Gym Management System. This affects an unknown part of the file /admin/add_trainers.php of the component Add New Trainer. The manipulation of the argument trainer_name leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-206013 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ New HTTP Request Smuggling Attacks Target Web Browsers πŸ•΄

Threat actors can abuse weaknesses in HTTP request handling to launch damaging browser-based attacks on website users, researcher says.

πŸ“– Read

via "Dark Reading".
πŸ•΄ New Open Source Tools Launched for Adversary Simulation πŸ•΄

The new open source tools are designed to help defense, identity and access management, and security operations center teams discover vulnerable network shares.

πŸ“– Read

via "Dark Reading".
❌ Cisco Confirms Network Breach Via Hacked Employee Google Account ❌

Networking giant says attackers gained initial access to an employee’s VPN client via a compromised Google account.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Black Hat USA: Deliberately vulnerable AWS, Azure cloud infrastructure is a pen tester’s playground πŸ—“οΈ

AWSGoat and AzureGoat tools showcased in Las Vegas this week

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Dark Reading News Desk: Live at Black Hat USA 2022 πŸ•΄

TODAY at 10 PT: Dark Reading News Desk returns to Black Hat USA 2022

πŸ“– Read

via "Dark Reading".
⚠ APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see… ⚠

If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

πŸ“– Read

via "Naked Security".
πŸ•΄ The Time Is Now for IoT Security Standards πŸ•΄

Industry standards would provide predictable and understandable IoT security frameworks.

πŸ“– Read

via "Dark Reading".