πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-36272 β€Ό

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ U.K. Water Supplier Hit with Clop Ransomware Attack ❌

The incident disrupted corporate IT systems at one company while attackers misidentified the victim in a post on its website that leaked stolen data.

πŸ“– Read

via "Threat Post".
πŸ•΄ Windows Vulnerability Could Crack DC Server Credentials Open πŸ•΄

The security flaw tracked as CVE-2022-30216 could allow attackers to perform server spoofing or trigger authentication coercion on the victim.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Legitimate hacking activities under UK law proposed by β€˜expert consensus’ πŸ—“οΈ

Contentious edge case activities are no excuse for further delaying of β€˜much overdue’ reform, say campaigners

πŸ“– Read

via "The Daily Swig".
πŸ•΄ With Plunge in Value, Cryptocurrency Crimes Decline in 2022 πŸ•΄

Cybercrime has been funded with cryptocurrency, but the valuation of various digital currencies has dropped by more than two-thirds and cybercriminals are feeling the pinch.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-38362 β€Ό

Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

πŸ“– Read

via "National Vulnerability Database".
⚠ Zoom for Mac patches get-root bug – update now! ⚠

There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

πŸ“– Read

via "Naked Security".
⚠ US offers reward β€œup to $10 million” for information about the Conti gang ⚠

Wanted - Reward Offered - Five unknown individuals (plus a man with a weird hat)

πŸ“– Read

via "Naked Security".
β™ŸοΈ When Efforts to Contain a Data Breach Backfire β™ŸοΈ

Earlier this month, the administrator of the cybercrime forum Breached received a cease-and-desist letter from a cybersecurity firm. The missive alleged that an auction on the site for data stolen from 10 million customers of Mexico’s second-largest bank was fake news and harming the bank’s reputation. The administrator responded to this empty threat by purchasing the stolen banking data and leaking it on the forum for everyone to download.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Name That Toon: Vicious Circle πŸ•΄

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-38192 β€Ό

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the userΓƒΒ’Γ’β€šΒ¬Γ’β€žΒ’s browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38193 β€Ό

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution in a victims browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38194 β€Ό

In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information from a properties file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Clop Ransomware Gang Breaches Water Utility, Just Not the Right One πŸ•΄

South Staffordshire in the UK has acknowledged it was targeted in a cyberattack, but Clop ransomware appears to be shaking down the wrong water company.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Disrupts Russian Group's Multiyear Cyber-Espionage Campaign πŸ•΄

"Seaborgium" is a highly persistent threat actor that has been targeting organizations and individuals of likely interest to the Russian government since at least 2017, company says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-2844 β€Ό

A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the file /wp/?cpmvc_id=1&cpmvc_do_action=mvparse&f=datafeed&calid=1&month_index=1&method=adddetails&id=2 of the component Calendar Handler. The manipulation of the argument Subject/Location/Description leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206487.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39085 β€Ό

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39086 β€Ό

IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2846 β€Ό

A vulnerability classified as problematic was found in Calendar Event Multi View Plugin. This vulnerability affects unknown code of the file /wp/?cpmvc_id=1&cpmvc_do_action=mvparse&f=datafeed&calid=1&month_index=1&method=adddetails&id=2. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The identifier of this vulnerability is VDB-206488.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38189 β€Ό

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the userÒ€ℒs browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39087 β€Ό

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109.

πŸ“– Read

via "National Vulnerability Database".