πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-3121 β€Ό

A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addemployee.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The identifier VDB-207853 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38367 β€Ό

The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ“’ TikTok reportedly suffers data breach πŸ“’

However, one researcher inspected some of the files and found it included publicly accessible data which could have been put together without a breach

πŸ“– Read

via "ITPro".
πŸ“’ China implies Washington behind University hack πŸ“’

Northwestern Polytechnical University’s cyber espionage case further strains US-China relations

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft Defender causes 'mass confusion' after legitimate apps trigger ransomware alerts πŸ“’

The broken update pushed to users on Sunday morning saw the likes of Teams, Slack, Chrome, and Edge all being confused with the dangerous Hive ransomware payloads

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-2714 β€Ό

Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2901 β€Ό

Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ Defenders Be Prepared: Cyberattacks Surge Against Linux Amid Cloud Migration πŸ•΄

Ransomware in particular poses a major threat, but security vendors say there has been an increase in Linux-targeted cryptojacking, malware, and vulnerability exploits as well, and defenders need to be ready.

πŸ“– Read

via "Dark Reading".
❀1
πŸ•΄ Botnets in the Age of Remote Work πŸ•΄

Here are some strategies for protecting the business against botnets poised to take advantage of remote-work vulnerabilities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cymulate Raises $70M Series D Funding for Continuous Security Posture Testing πŸ•΄

Investor participation from prior round demonstrates confidence in the company's current and future performance.

πŸ“– Read

via "Dark Reading".
⚠ Chrome and Edge fix zero-day security hole – update now! ⚠

This time, the crooks got there first - only 1 security hole patched, but it's a zero-day.

πŸ“– Read

via "Naked Security".
πŸ•΄ The 3 Fundamentals of Building an Effective IoMT Security Strategy πŸ•΄

The high stakes and unique priorities for Internet of Medical Things devices require specialized cybersecurity strategies.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Internet Security & Encryption Pioneer Peter Eckersley Passes at 43 πŸ•΄

The founder of Let's Encrypt and an EFF technologist, Eckersley devoted his life's work to making the Internet safer and more secure.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-40111 β€Ό

In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37841 β€Ό

In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37839 β€Ό

TOTOLINK A860R V4.1.2cu.5182_B20201027 is vulnerable to Buffer Overflow via Cstecgi.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36584 β€Ό

In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40110 β€Ό

TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26114 β€Ό

An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37842 β€Ό

In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43076 β€Ό

An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and below may allow a remote authenticated attacker with restricted user profile to modify the system files using the shell access.

πŸ“– Read

via "National Vulnerability Database".