πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-40816 β€Ό

Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see personal information of other users. This logic was not effective when used through a web socket connection, so that a logged-in attacker would be able to fetch personal data of other users by querying the Zammad API. This issue is fixed in , 5.2.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40354 β€Ό

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40877 β€Ό

Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the Γ’β‚¬ΛœidÒ€ℒ parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23006 β€Ό

A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version file. This vulnerability can only be exploited by chaining it with another issue. If an attacker is able to carry out a remote code execution attack, they can gain access to the vulnerable file, due to the presence of insecure functions in code. User interaction is required for exploitation. Exploiting the vulnerability could result in exposure of information, ability to modify files, memory access errors, or system crashes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37193 β€Ό

Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from access revocation evasion attacks once the malicious sharee obtains the access credentials.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Infosec Partners announces new XZERO Early Warning System πŸ“’

New cyberattack detection service serves up real-time information on suspect activity and advance notice of imminent security incidents

πŸ“– Read

via "ITPro".
πŸ“’ FARGO ransomware targets vulnerable Microsoft SQL servers in new wave of attacks πŸ“’

Victims who don't pay the ransom risk having their stolen files exposed on the threat actor's Telegram channel

πŸ“– Read

via "ITPro".
πŸ“’ Australia looks to amend privacy rules following Optus data breach πŸ“’

The breach is currently being investigated by the Australian Federal Police

πŸ“– Read

via "ITPro".
πŸ“’ Vectra appoints Nuvias Group as sole UK distributor πŸ“’

The AI-based threat detection and response provider will leverage Nuvias’ 1,600-strong UK partner network

πŸ“– Read

via "ITPro".
πŸ“’ CIO Priorities: 2020 vs 2023 πŸ“’

Zero Trust, SaaS Security, and its impact on SD-WAN being a priority

πŸ“– Read

via "ITPro".
πŸ“’ 1.1 million Tesla cars recalled over software glitch πŸ“’

The mass recall is prompted by a flaw in the vehicles' automatic window reversal system

πŸ“– Read

via "ITPro".
πŸ“’ Fancy Bear hackers exploit PowerPoint files to spread Graphite malware πŸ“’

The ongoing attack reportedly targets entities in the defense and government sectors of the European Union and Eastern European nations

πŸ“– Read

via "ITPro".
πŸ“’ TikTok considers changes to data policies amid rising security concerns πŸ“’

The ByteDance-owned app also faces a potential Β£27m fine over privacy violations

πŸ“– Read

via "ITPro".
πŸ“’ Mozilla patches high-severity security flaws in new β€˜speedy’ Firefox release πŸ“’

Numerous vulnerabilities across Mozilla's products could potentially lead to code execution and system takeover

πŸ“– Read

via "ITPro".
πŸ“’ Cloudflare unveils first zero trust SIM for mobile devices πŸ“’

New wireless carrier program will also let carriers integrate Zero Trust security into existing corporate plans

πŸ“– Read

via "ITPro".
πŸ“’ GitHub alerts users to active phishing campaign πŸ“’

The attack revolves around counterfeit CircleCI notifications urging users to accept updated terms of use and privacy policy

πŸ“– Read

via "ITPro".
πŸ“’ 35 cyber startups join largest UK government-backed accelerator πŸ“’

The startups will benefit from business masterclasses, mentoring and engineering support, and technical product development support

πŸ“– Read

via "ITPro".
πŸ“’ GoTo Resolve Basic review: An SMB-friendly remote support service πŸ“’

This good-value hosted remote support service is ideal for SMBs that demand zero-trust access security

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-32168 β€Ό

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3333 β€Ό

A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.2.5 is able to address this issue. It is recommended to upgrade the affected component. VDB-209370 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3332 β€Ό

A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System. This affects an unknown part of the file router.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-209583.

πŸ“– Read

via "National Vulnerability Database".