πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25304 β€Ό

All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ GitLab patches critical remote code execution bug πŸ—“οΈ

Update now to protect against security vulnerability

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-2956 β€Ό

A vulnerability classified as problematic has been found in ConsoleTVs Noxen. Affected is an unknown function of the file /Noxen-master/users.php. The manipulation of the argument create_user_username with the input "><script>alert(/xss/)</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-207000.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28817 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: No impact could be verified. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1989 β€Ό

All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.

πŸ“– Read

via "National Vulnerability Database".
❌ Firewall Bug Under Active Attack Triggers CISA Warning ❌

CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Security researchers blast β€˜ridiculous’ CrowdStrike bug disclosure practices πŸ—“οΈ

The vulnerability might not be noteworthy, but the reporting process may be A security firm has criticized CrowdStrike for operating a β€œridiculous” bug bounty disclosure program following a sensor fla

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-37199 β€Ό

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35203 β€Ό

An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  I2P 1.9.0 πŸ› 

I2P is an anonymizing network, offering a simple layer that identity-sensitive applications can use to securely communicate. All data is wrapped with several layers of encryption, and the network is both distributed and dynamic, with no trusted parties. This is the source code release version.

πŸ“– Read

via "Packet Storm Security".
⚠ Laptop denial-of-service via music: the 1980s R&B song with a CVE! ⚠

We haven't validated this vuln ourselves... but the source of the story is impeccable. (Impeccably dressed, at least.)

πŸ“– Read

via "Naked Security".
πŸ‘2
⚠ Bitcoin ATMs leeched by attackers who created fake admin accounts ⚠

The criminals didn't implant any malware. The attack was orchestrated via malevolent configuration changes.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-37223 β€Ό

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35278 β€Ό

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

πŸ“– Read

via "National Vulnerability Database".
πŸ” FBI Warns Proxies, Configurations Seen in More Credential Stuffing Attacks πŸ”

Attackers are using proxies and configurations to mask and automate credential stuffing attacks on US companies, the FBI warns.

πŸ“– Read

via "".
β€Ό CVE-2021-23177 β€Ό

An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3763 β€Ό

A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3714 β€Ό

A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20316 β€Ό

A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3800 β€Ό

A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3839 β€Ό

A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

πŸ“– Read

via "National Vulnerability Database".