πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-2379 β€Ό

The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2818 β€Ό

Authentication Bypass by Primary Weakness in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37401 β€Ό

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulnerable to a brute force attack if an attacker has access to the users stored config. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26307 - LibreOffice

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Healthcare provider Novant issues data breach warning after site tracking pixels sent patients’ information to Meta servers πŸ—“οΈ

Leaked data potentially included patients’ email addresses, phone numbers, and device IP addresses

πŸ“– Read

via "The Daily Swig".
πŸ‘1
❌ Black Hat and DEF CON Roundup ❌

β€˜Summer Camp’ for hackers features a compromised satellite, a homecoming for hackers and cyberwarfare warnings.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Germany to mandate minimum security standards for web browsers in government πŸ—“οΈ

Less celebrated browsers and deprecated applications like Internet Explorer will be browsers non-grata

πŸ“– Read

via "The Daily Swig".
πŸ•΄ How and Why to Apply OSINT to Protect the Enterprise πŸ•΄

Here's how to flip the tide and tap open source intelligence to protect your users.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-33990 β€Ό

Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33992 β€Ό

DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33988 β€Ό

dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID value is known to the attacker.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34294 β€Ό

totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33989 β€Ό

dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33991 β€Ό

dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36262 β€Ό

An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33993 β€Ό

Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.

πŸ“– Read

via "National Vulnerability Database".
⚠ Zoom for Mac patches get-root bug – update now! ⚠

There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-36525 β€Ό

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35623 β€Ό

In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control packets and access packets with the same SeqAuth

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36526 β€Ό

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36524 β€Ό

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2824 β€Ό

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.1.

πŸ“– Read

via "National Vulnerability Database".