๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ—“๏ธ Legitimate hacking activities under UK law proposed by โ€˜expert consensusโ€™ ๐Ÿ—“๏ธ

Contentious edge case activities are no excuse for further delaying of โ€˜much overdueโ€™ reform, say campaigners

๐Ÿ“– Read

via "The Daily Swig".
๐Ÿ•ด With Plunge in Value, Cryptocurrency Crimes Decline in 2022 ๐Ÿ•ด

Cybercrime has been funded with cryptocurrency, but the valuation of various digital currencies has dropped by more than two-thirds and cybercriminals are feeling the pinch.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ‘1
โ€ผ CVE-2022-38362 โ€ผ

Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  Zoom for Mac patches get-root bug โ€“ update now! โš 

There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

๐Ÿ“– Read

via "Naked Security".
โš  US offers reward โ€œup to $10 millionโ€ for information about the Conti gang โš 

Wanted - Reward Offered - Five unknown individuals (plus a man with a weird hat)

๐Ÿ“– Read

via "Naked Security".
โ™Ÿ๏ธ When Efforts to Contain a Data Breach Backfire โ™Ÿ๏ธ

Earlier this month, the administrator of the cybercrime forum Breached received a cease-and-desist letter from a cybersecurity firm. The missive alleged that an auction on the site for data stolen from 10 million customers of Mexicoโ€™s second-largest bank was fake news and harming the bankโ€™s reputation. The administrator responded to this empty threat by purchasing the stolen banking data and leaking it on the forum for everyone to download.

๐Ÿ“– Read

via "Krebs on Security".
๐Ÿ•ด Name That Toon: Vicious Circle ๐Ÿ•ด

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-38192 โ€ผ

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the userรƒยขรขโ€šยฌรขโ€žยขs browser.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38193 โ€ผ

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution in a victims browser.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38194 โ€ผ

In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information from a properties file.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Clop Ransomware Gang Breaches Water Utility, Just Not the Right One ๐Ÿ•ด

South Staffordshire in the UK has acknowledged it was targeted in a cyberattack, but Clop ransomware appears to be shaking down the wrong water company.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Microsoft Disrupts Russian Group's Multiyear Cyber-Espionage Campaign ๐Ÿ•ด

"Seaborgium" is a highly persistent threat actor that has been targeting organizations and individuals of likely interest to the Russian government since at least 2017, company says.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-2844 โ€ผ

A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the file /wp/?cpmvc_id=1&cpmvc_do_action=mvparse&f=datafeed&calid=1&month_index=1&method=adddetails&id=2 of the component Calendar Handler. The manipulation of the argument Subject/Location/Description leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206487.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-39085 โ€ผ

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-39086 โ€ผ

IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-2846 โ€ผ

A vulnerability classified as problematic was found in Calendar Event Multi View Plugin. This vulnerability affects unknown code of the file /wp/?cpmvc_id=1&cpmvc_do_action=mvparse&f=datafeed&calid=1&month_index=1&method=adddetails&id=2. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The identifier of this vulnerability is VDB-206488.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38189 โ€ผ

A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the userรขโ‚ฌโ„ขs browser.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-39087 โ€ผ

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-39035 โ€ผ

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213965.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38184 โ€ผ

There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-2843 โ€ผ

A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /wp-admin/admin-ajax.php of the component Quick Edit. The manipulation of the argument post_title with the input <img src=x onerror=alert`2`> leads to cross site scripting. The attack may be launched remotely. VDB-206486 is the identifier assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".