πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Multiple cloud vendors impacted by PostgreSQL vulnerability that exposed enterprise databases πŸ—“οΈ

Flaws discovered in various PostgreSQL-as-a-Service offerings, including those from Microsoft and Google

πŸ“– Read

via "The Daily Swig".
πŸ•΄ SEPT. 7-9: Ukraine, Election, AI, Cybercrime, 5G Among Topics Explored by 125+ Speakers at 13th Billington Cybersecurity Summit πŸ•΄

Heads of CIA and CISA headline event at DC Convention Center.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Lessons From the Cybersecurity Trenches πŸ•΄

Threat hunting not only serves the greater good by helping keep users safe, it rewards practitioners with the thrill of the hunt and solving of complex problems. Tap into your background and learn to follow your instincts.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-36599 β€Ό

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30490 β€Ό

upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36530 β€Ό

An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29959 β€Ό

Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36273 β€Ό

Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30264 β€Ό

The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36272 β€Ό

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ U.K. Water Supplier Hit with Clop Ransomware Attack ❌

The incident disrupted corporate IT systems at one company while attackers misidentified the victim in a post on its website that leaked stolen data.

πŸ“– Read

via "Threat Post".
πŸ•΄ Windows Vulnerability Could Crack DC Server Credentials Open πŸ•΄

The security flaw tracked as CVE-2022-30216 could allow attackers to perform server spoofing or trigger authentication coercion on the victim.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Legitimate hacking activities under UK law proposed by β€˜expert consensus’ πŸ—“οΈ

Contentious edge case activities are no excuse for further delaying of β€˜much overdue’ reform, say campaigners

πŸ“– Read

via "The Daily Swig".
πŸ•΄ With Plunge in Value, Cryptocurrency Crimes Decline in 2022 πŸ•΄

Cybercrime has been funded with cryptocurrency, but the valuation of various digital currencies has dropped by more than two-thirds and cybercriminals are feeling the pinch.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-38362 β€Ό

Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

πŸ“– Read

via "National Vulnerability Database".
⚠ Zoom for Mac patches get-root bug – update now! ⚠

There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

πŸ“– Read

via "Naked Security".
⚠ US offers reward β€œup to $10 million” for information about the Conti gang ⚠

Wanted - Reward Offered - Five unknown individuals (plus a man with a weird hat)

πŸ“– Read

via "Naked Security".
β™ŸοΈ When Efforts to Contain a Data Breach Backfire β™ŸοΈ

Earlier this month, the administrator of the cybercrime forum Breached received a cease-and-desist letter from a cybersecurity firm. The missive alleged that an auction on the site for data stolen from 10 million customers of Mexico’s second-largest bank was fake news and harming the bank’s reputation. The administrator responded to this empty threat by purchasing the stolen banking data and leaking it on the forum for everyone to download.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Name That Toon: Vicious Circle πŸ•΄

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-38192 β€Ό

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the userΓƒΒ’Γ’β€šΒ¬Γ’β€žΒ’s browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38193 β€Ό

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution in a victims browser.

πŸ“– Read

via "National Vulnerability Database".