πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24951 β€Ό

A race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Terminal's IPC socket, enabling access to Eternal Terminal clients which attempt to connect in the future.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38216 β€Ό

An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36309 β€Ό

Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯1
❌ Xiaomi Phone Bug Allowed Payment Forgery ❌

Mobile transactions could’ve been disabled, created and signed by attackers.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-2838 β€Ό

In Eclipse SphinxΓ’β€žΒ’ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Multiple cloud vendors impacted by PostgreSQL vulnerability that exposed enterprise databases πŸ—“οΈ

Flaws discovered in various PostgreSQL-as-a-Service offerings, including those from Microsoft and Google

πŸ“– Read

via "The Daily Swig".
πŸ•΄ SEPT. 7-9: Ukraine, Election, AI, Cybercrime, 5G Among Topics Explored by 125+ Speakers at 13th Billington Cybersecurity Summit πŸ•΄

Heads of CIA and CISA headline event at DC Convention Center.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Lessons From the Cybersecurity Trenches πŸ•΄

Threat hunting not only serves the greater good by helping keep users safe, it rewards practitioners with the thrill of the hunt and solving of complex problems. Tap into your background and learn to follow your instincts.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-36599 β€Ό

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30490 β€Ό

upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36530 β€Ό

An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29959 β€Ό

Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36273 β€Ό

Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30264 β€Ό

The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36272 β€Ό

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ U.K. Water Supplier Hit with Clop Ransomware Attack ❌

The incident disrupted corporate IT systems at one company while attackers misidentified the victim in a post on its website that leaked stolen data.

πŸ“– Read

via "Threat Post".
πŸ•΄ Windows Vulnerability Could Crack DC Server Credentials Open πŸ•΄

The security flaw tracked as CVE-2022-30216 could allow attackers to perform server spoofing or trigger authentication coercion on the victim.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Legitimate hacking activities under UK law proposed by β€˜expert consensus’ πŸ—“οΈ

Contentious edge case activities are no excuse for further delaying of β€˜much overdue’ reform, say campaigners

πŸ“– Read

via "The Daily Swig".
πŸ•΄ With Plunge in Value, Cryptocurrency Crimes Decline in 2022 πŸ•΄

Cybercrime has been funded with cryptocurrency, but the valuation of various digital currencies has dropped by more than two-thirds and cybercriminals are feeling the pinch.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-38362 β€Ό

Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

πŸ“– Read

via "National Vulnerability Database".
⚠ Zoom for Mac patches get-root bug – update now! ⚠

There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

πŸ“– Read

via "Naked Security".