πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-29922 β€Ό

Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro SYS600. The vulnerability may cause a denial-of-service on the IEC 61850 OPC Server part of the SYS600 product. This issue affects: Hitachi Energy MicroSCADA Pro SYS600 version 9.4 FP2 Hotfix 4 and earlier versions Hitachi Energy MicroSCADA X SYS600 version 10 to version 10.3.1. cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.0:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2277 β€Ό

Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP communication establishment causes a denial-of-service when ICCP of SYS600 is request to forward any data item updates with timestamps too distant in the future to any remote ICCP system. By default, ICCP is not configured and not enabled. This issue affects: Hitachi Energy MicroSCADA X SYS600 version 10.2 to version 10.3.1. cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Say Hello to Crazy Thin β€˜Deep Insert’ ATM Skimmers β™ŸοΈ

A number of financial institutions in and around New York City are dealing with a rash of super-thin "deep insert" card skimming devices designed to fit inside the mouth of an ATM's card acceptance slot. The card skimmers are paired with tiny pinhole cameras that are cleverly disguised as part of the cash machine. Here's a look at some of the more sophisticated deep insert skimmer technology that fraud investigators have recently found in the wild.

πŸ“– Read

via "Krebs on Security".
πŸ‘2
πŸ“’ Infinigate becomes sole distributor of the Cybereason Defense Platform in Europe πŸ“’

Exclusive distribution agreement aims to help more organisations detect and respond to cyberattacks at speed and scale

πŸ“– Read

via "ITPro".
πŸ“’ Cisco confirms data breach following Yanluowang ransomware attack in May πŸ“’

The tech giant insists its business was unaffected by the attack

πŸ“– Read

via "ITPro".
πŸ“’ Gartner: Most businesses are dropping security vendors to improve cyber resiliency πŸ“’

The vast majority of organisations around the world are pursuing vendor consolidation to improve security and decrease complexity

πŸ“– Read

via "ITPro".
πŸ“’ Apple patches yet another zero-day flaw in substantial security update πŸ“’

The updates include fixes for kernel-level code execution bugs, privacy issues, and more - all impacting iPhone and iPad users

πŸ“– Read

via "ITPro".
πŸ“’ US Commerce Department inks deal with Google to develop chips for researchers πŸ“’

The news breaks weeks after the US restricted CHIPS-funded companies' investments in China

πŸ“– Read

via "ITPro".
πŸ“’ Sophos XGS 116 review: A small and mighty appliance πŸ“’

This clever and compact security gateway brings outstanding security and remote management features at a tempting price

πŸ“– Read

via "ITPro".
πŸ“’ Exertis Enterprise announces expanded Progress partnership πŸ“’

Distributor moves to strengthen NetSecOps in the UK with availability of Progress WhatsUp Gold and Progress Flowmon

πŸ“– Read

via "ITPro".
πŸ“’ U-Haul data breach exposes customer data πŸ“’

Despite the scope of the attack, the company affirmed the hack did not compromise customers’ payment card information

πŸ“– Read

via "ITPro".
πŸ“’ Three critical vulnerabilities and one zero-day feature in Microsoft's September Patch Tuesday πŸ“’

Several issues in the monthly update require 'urgent' attention but September's Patch Tuesday only brings around half the fixes that came in August

πŸ“– Read

via "ITPro".
πŸ“’ Trend Micro cautions against actively exploited Apex One RCE vulnerability πŸ“’

The firm also patched a high severity security flaw that lets perpetrators bypass authentication

πŸ“– Read

via "ITPro".
πŸ“’ WordPress plugin vulnerability leaves sites open to total takeover πŸ“’

Customers on WordFence's paid tiers will get protection from the WPGate exploit right away, but those on the free-tier face a 30-day delay

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-40734 β€Ό

UniSharp laravel-filemanager (aka Laravel Filemanager) through 2.5.1 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36603 β€Ό

The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys driver must first be installed by a user with administrative privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3221 β€Ό

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3222 β€Ό

Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31735 β€Ό

OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ WAPPLES web application firewall faulted for multiple flaws πŸ—“οΈ

Researcher uncovers RCE and undocumented backdoor risks

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Open source CMS TYPO3 tackles XSS vulnerability πŸ—“οΈ

Bug spawned by parsing problem in upstream package

πŸ“– Read

via "The Daily Swig".