πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Fake DDoS Protection Alerts Distribute Dangerous RAT πŸ•΄

Security vendor Sucuri says adversaries are injecting malicious JavaScript into numerous WordPress websites that triggers phony bot-related checks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Facing the New Security Challenges That Come With Cloud πŸ•΄

Organizations relying on multicloud or hybrid-cloud environments without ο»Ώa true understanding of their security vulnerabilities do so at their peril.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-35191 β€Ό

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

πŸ“– Read

via "National Vulnerability Database".
πŸ€”1
β€Ό CVE-2022-2829 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-25075 β€Ό

HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33916 β€Ό

OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34919 β€Ό

The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28861 β€Ό

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42232 β€Ό

TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the router.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35992 β€Ό

Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would be able to decrypt the password stored within the configuration file. This would yield cleartext credentials for the database (to gain access to financial records of customers stored within the database), and in some cases would allow remote login to the database.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-35733 β€Ό

Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24381 β€Ό

All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24298 β€Ό

All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25304 β€Ό

All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ GitLab patches critical remote code execution bug πŸ—“οΈ

Update now to protect against security vulnerability

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-2956 β€Ό

A vulnerability classified as problematic has been found in ConsoleTVs Noxen. Affected is an unknown function of the file /Noxen-master/users.php. The manipulation of the argument create_user_username with the input "><script>alert(/xss/)</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-207000.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28817 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: No impact could be verified. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1989 β€Ό

All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.

πŸ“– Read

via "National Vulnerability Database".
❌ Firewall Bug Under Active Attack Triggers CISA Warning ❌

CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Security researchers blast β€˜ridiculous’ CrowdStrike bug disclosure practices πŸ—“οΈ

The vulnerability might not be noteworthy, but the reporting process may be A security firm has criticized CrowdStrike for operating a β€œridiculous” bug bounty disclosure program following a sensor fla

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-37199 β€Ό

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.

πŸ“– Read

via "National Vulnerability Database".