πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-36747 β€Ό

Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel().

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36749 β€Ό

RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36746 β€Ό

LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39047 β€Ό

Freeciv before 2.6.7 and before 3.0.3 is prone to a buffer overflow vulnerability in the Modpack Installer utility's handling of the modpack URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37021 β€Ό

Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15 and Java 11. If upgrading to Java 11 is not possible, then upgrade to Apache Geode 1.15 and specify "--J=-Dgeode.enableGlobalSerialFilter=true" when starting any Locators or Servers. Follow the documentation for details on specifying any user classes that may be serialized/deserialized with the "serializable-object-filter" configuration option. Using a global serial filter will impact performance.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37023 β€Ό

Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Apache Geode 1.15 and follow the documentation for details on enabling "validate-serializable-objects=true" and specifying any user classes that may be serialized/deserialized with "serializable-object-filter". Enabling "validate-serializable-objects" may impact performance.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37022 β€Ό

Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15. Use of 1.15 on Java 11 will automatically protect JMX over RMI against deserialization attacks. This should have no impact on performance since it only affects JMX/RMI which Gfsh uses to communicate with the JMX Manager which is hosted on a Locator.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39046 β€Ό

An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.

πŸ“– Read

via "National Vulnerability Database".
⚠ JavaScript bugs aplenty in Node.js ecosystem – found automatically ⚠

How to get the better of bugs in all the possible packages in your supply chain?

πŸ“– Read

via "Naked Security".
⚠ Chrome patches 24 security holes, enables β€œSanitizer” safety system ⚠

24 existing bugs fixed. And, we hope, numerous potential future bugs prevented.

πŸ“– Read

via "Naked Security".
❌ Student Loan Breach Exposes 2.5M Records ❌

2.5 million people were affected, in a breach that could spell more trouble down the line.

πŸ“– Read

via "Threat Post".
πŸ•΄ SecureAuth Announces General Availability of Arculix, Its Next-Gen Passwordless, Continuous-Authentication Platform πŸ•΄

Next-gen platform delivers adaptive and robust, continuous authentication with identity orchestration and a frictionless user experience.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Inevitability of Cloud Breaches: Tales of Real-World Cloud Attacks πŸ•΄

While cloud breaches are going to happen, that doesn't mean we can't do anything about them. By better understanding cloud attacks, organizations can better prepare for them. (First of two parts.)

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Command injection vulnerability in GitHub Pages nets bug hunter $4k πŸ—“οΈ

Exploit involved duping developers into exposing repositories with social engineering techniques

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Three-day hackathon uncovers hundreds of bugs in Yahoo search engine tool Vespa πŸ—“οΈ

Live event brings together bug bounty hunters from across the globe

πŸ“– Read

via "The Daily Swig".
β™ŸοΈ Final Thoughts on Ubiquiti β™ŸοΈ

Last year, I posted a series of articles about a purported β€œbreach” at Ubiquiti. My sole source for that reporting was the person who has since been indicted by federal prosecutors for his alleged wrongdoing – which includes providing false… Read More Β»

πŸ“– Read

via "Krebs on Security".
πŸ•΄ TikTok for Android Bug Allows Single-Click Account Hijack πŸ•΄

A security vulnerability (CVE-2022-28799) in one of TikTok for Android's deeplinks could affect billions of users, Microsoft warns.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-36045 β€Ό

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in essentially all versions of NodeBB (as far back as v1.0.1 and potentially earlier) used a cryptographically insecure Pseudo-random number generator (`Math.random()`), which meant that a specially crafted script combined with multiple invocations of the password reset functionality could enable an attacker to correctly calculate the reset code for an account they do not have access to. This vulnerability impacts all installations of NodeBB. The vulnerability allows for an attacker to take over any account without the involvement of the victim, and as such, the remediation should be applied immediately (either via NodeBB upgrade or cherry-pick of the specific changeset. The vulnerability has been patched in version 2.x and 1.19.x. There is no known workaround, but the patch sets listed above will fully patch the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36035 β€Ό

Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automating updates to configuration when there is new code to deploy. Flux CLI allows users to deploy Flux components into a Kubernetes cluster via command-line. The vulnerability allows other applications to replace the Flux deployment information with arbitrary content which is deployed into the target Kubernetes cluster instead. The vulnerability is due to the improper handling of user-supplied input, which results in a path traversal that can be controlled by the attacker. Users sharing the same shell between other applications and the Flux CLI commands could be affected by this vulnerability. In some scenarios no errors may be presented, which may cause end users not to realize that something is amiss. A safe workaround is to execute Flux CLI in ephemeral and isolated shell environments, which can ensure no persistent values exist from previous processes. However, upgrading to the latest version of the CLI is still the recommended mitigation strategy.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ (ISC)Β² Opens Global Enrollment for '1 Million Certified in Cybersecurity' Initiative πŸ•΄

(ISC)Β² pledges to expand and diversify the cybersecurity workforce by providing free "(ISC)Β² Certified in Cybersecurity" education and exams to 1 million people worldwide.

πŸ“– Read

via "Dark Reading".
πŸ•΄ OpenText Goes All-in on Cybersecurity Size and Scale With Micro Focus Purchase πŸ•΄

OpenText makes a $6 billion bet that bigger is better in security and that cybersecurity platform plays are the future.

πŸ“– Read

via "Dark Reading".