πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-35476 β€Ό

OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbc0b.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38233 β€Ό

XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::readMCURow() at /xpdf/Stream.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38235 β€Ό

XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::getChar() at /xpdf/Stream.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38237 β€Ό

XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38236 β€Ό

XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38238 β€Ό

XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38230 β€Ό

XPDF commit ffaf11c was discovered to contain a floating point exception (FPE) via DCTStream::decodeImage() at /xpdf/Stream.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38234 β€Ό

XPDF commit ffaf11c was discovered to contain a segmentation violation via Lexer::getObj(Object*) at /xpdf/Lexer.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38231 β€Ό

XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35434 β€Ό

jpeg-quantsmooth before commit 8879454 contained a floating point exception (FPE) via /jpeg-quantsmooth/jpegqs+0x4f5d6c.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Rolls Out Tamper Protection for Macs πŸ•΄

The tamper protection feature detects attempts to modify files and processes for Microsoft Defender for Endpoints on macOS.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-25799 β€Ό

An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.5.0. An attacker could send a link that has a specially crafted URL and convince the user to click the link. When an authenticated user clicks the link, the authenticated user's browser could be redirected to a malicious site that is designed to impersonate a legitimate website. The attacker could trick the user and potentially acquire sensitive information such as the user's credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42052 β€Ό

IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2871 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Developers still struggling with security issues during code reviews, study finds πŸ—“οΈ

The road to DevSecOps isn’t always the smoothest

πŸ“– Read

via "The Daily Swig".
πŸ‘1
⚠ US offers reward β€œup to $10 million” for information about the Conti gang ⚠

Wanted - Reward Offered - Five unknown individuals (plus a man with a weird hat)

πŸ“– Read

via "Naked Security".
⚠ Chrome browser gets 11 security fixes with 1 zero-day – update now! ⚠

Don't delay - patch today.

πŸ“– Read

via "Naked Security".
πŸ‘1
πŸ•΄ 7 Smart Ways to Secure Your E-Commerce Site πŸ•΄

Especially if your e-commerce and CMS platforms are integrated, you risk multiple potential sources of intrusion, and the integration points themselves may be vulnerable to attack.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-37459 β€Ό

Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-45454 β€Ό

Ampere Altra before SRP 1.08b and Altra Max? before SRP 2.05 allow information disclosure of power telemetry via HWmon.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Swiss Post relaunches e-voting bug bounty program πŸ—“οΈ

Ethical hackers invited to stress test election infrastructure

πŸ“– Read

via "The Daily Swig".