πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-36680 β€Ό

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37151 β€Ό

There is an unauthorized access vulnerability in Online Diagnostic Lab Management System 1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39393 β€Ό

mm-wiki v0.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the markdown editor.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36683 β€Ό

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36682 β€Ό

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40285 β€Ό

htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39394 β€Ό

mm-wiki v0.2.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add user accounts and modify user information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36679 β€Ό

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36681 β€Ό

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37150 β€Ό

An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstname, address, middlename, lastname , gender, email, contact parameters.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep97: Did your iPhone get pwned? How would you know? [Audio + Text] ⚠

Latest episode - listen now! (Or read the transcript if you prefer the text version.)

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-36521 β€Ό

Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.

πŸ“– Read

via "National Vulnerability Database".
⚠ Firefox 104 is out – no critical bugs, but update anyway ⚠

Two trust-spoofing bugs were the main culprits this month - but neither one was a zero-day.

πŸ“– Read

via "Naked Security".
πŸ•΄ 'Sliver' Emerges as Cobalt Strike Alternative for Malicious C2 πŸ•΄

Microsoft and others say they have observed nation-state actors, ransomware purveyors, and assorted cybercriminals pivoting to an open source attack-emulation tool in recent campaigns.

πŸ“– Read

via "Dark Reading".
❌ Ransomware Attacks are on the Rise ❌

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

πŸ“– Read

via "Threat Post".
πŸ” Friday Five 8/26 πŸ”

Read about why Twitter is coming under fire, how a cybersecurity organization may have gone on the offensive, possible big changes coming for software vendors, and much more in this week’s Friday Five!


πŸ“– Read

via "".
πŸ“’ Snapchat settles for $35 million in Illinois biometrics lawsuit πŸ“’

The social media giant had been accused of improperly collecting, storing facial geometry in violation of state legislation

πŸ“– Read

via "ITPro".
πŸ“’ SolarWinds hackers strike again with a new β€œMagicWeb” authentication exploit πŸ“’

Microsoft warns MagicWeb can abuse admin credentials to hijack AD FS enterprise identity system

πŸ“– Read

via "ITPro".
πŸ“’ PyPI packages succumb to Mailchimp phishing scam πŸ“’

The news comes after "fairly convincing" phishing emails from a Mailchimp account swindled developers into revealing credentials

πŸ“– Read

via "ITPro".
πŸ“’ French telco giant Altice reportedly hit by Hive ransomware attack πŸ“’

Dark web listings indicate that the French multinational was attacked in early August, but the company has made no announcement

πŸ“– Read

via "ITPro".
πŸ“’ Companies House reveals overhaul to WebFiling accounts system πŸ“’

Businesses will be able to control those with filing permissions more easily, as the new accounts mark a new streamlining of the government's digital filing requirements

πŸ“– Read

via "ITPro".