πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-27602 β€Ό

BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20320 β€Ό

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20253 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-15334 β€Ό

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40694 β€Ό

Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20237 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1725 β€Ό

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20295 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20251 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20272 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20280 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20283 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
⚠ Optus breach – Aussie telco told it will have to pay to replace IDs ⚠

Licence compromised? Passport number burned? Need a new one? Who's going to pay?

πŸ“– Read

via "Naked Security".
πŸ•΄ What Lurks in the Shadows of Cloud Security? πŸ•΄

Organizations looking to get ahead in cloud security have gone down the path of deploying CSPM tooling with good results. Still, there’s a clear picture that data security and security operations are next key areas of interest.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Patching common vulnerabilities at scale: project promises bulk pull requests πŸ—“οΈ

Automating bulk pull request generation FTW

πŸ“– Read

via "The Daily Swig".
πŸ•΄ XSS Flaw in Prevalent Media Imaging Tool Exposes Trove of Patient Data πŸ•΄

Bugs in Canon Medical's Virea View could allow cyberattackers to access several sources of sensitive patient data.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Why the US Should Help Secure Mexican Infrastructure β€” and What It Gets in Return πŸ•΄

Call it cross-border enlightened self-interest: As one of the US's premier trade partners and closest neighbors, what's bad for Mexico is bad for the US.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-40890 β€Ό

A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40475 β€Ό

TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40363 β€Ό

A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3352 β€Ό

Use After Free in GitHub repository vim/vim prior to 9.0.0614.

πŸ“– Read

via "National Vulnerability Database".