βΌ CVE-2022-41294 βΌ
π Read
via "National Vulnerability Database".
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807.π Read
via "National Vulnerability Database".
βΌ CVE-2022-42457 βΌ
π Read
via "National Vulnerability Database".
Generex CS141 before 2.08 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can occur via a reverse shell installed by install.sh).π Read
via "National Vulnerability Database".
βΌ CVE-2022-39279 βΌ
π Read
via "National Vulnerability Database".
discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some places render a chat channel's name and description in an unsafe way, allowing staff members to cause an cross site scripting (XSS) attack by inserting unsafe HTML into them. Version 0.9 has addressed this issue. Users are advised to upgrade. There are no known workarounds for this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27810 βΌ
π Read
via "National Vulnerability Database".
It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39284 βΌ
π Read
via "National Vulnerability Database".
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exposed to scripts. It should be noted that this vulnerability does not affect session cookies. Users are advised to upgrade to v4.2.7 or later. Users unable to upgrade are advised to manually construct their cookies either by setting the options in code or by constructing Cookie objects. Examples of each workaround are available in the linked GHSA.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41355 βΌ
π Read
via "National Vulnerability Database".
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /leave_system/classes/Master.php?f=delete_department.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26236 βΌ
π Read
via "National Vulnerability Database".
The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26238 βΌ
π Read
via "National Vulnerability Database".
The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40494 βΌ
π Read
via "National Vulnerability Database".
NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.π Read
via "National Vulnerability Database".
π΄ Sharing Knowledge at 44CON π΄
π Read
via "Dark Reading".
The infosec conference named after the UK's calling code returned this year with a focus on building a healthy community.π Read
via "Dark Reading".
Darkreading
Sharing Knowledge at 44CON
The infosec conference named after the UK's calling code returned this year with a focus on building a healthy community.
π’ China cracks down on citizens' anti-censorship tools with Great Firewall upgrades π’
π Read
via "ITPro".
This new discovery comes a week before a predicted major reshuffle of leadership in the Chinese Communist Partyπ Read
via "ITPro".
IT PRO
China cracks down on citizens' anti-censorship tools with Great Firewall upgrades | IT PRO
This new discovery comes a week before a predicted major reshuffle of leadership in the Chinese Communist Party
π’ Sophos 2021 Antivirus solutions review π’
π Read
via "ITPro".
Low-cost consumer security products for Mac and Windowsπ Read
via "ITPro".
IT PRO
Sophos 2021 Antivirus solutions review | IT PRO
Low-cost consumer security products for Mac and Windows
π’ Canadian Netwalker ransomware affiliate faces 20 years in prison and $21.5 million fine π’
π Read
via "ITPro".
The Canadian hacker was arrested in Quebec after a search revealed 719 Bitcoin and hundreds of thousands of Canadian dollars believed to be stolen fundsπ Read
via "ITPro".
IT PRO
Canadian Netwalker ransomware affiliate faces 20 years in prison and $21.5 million fine | IT PRO
The Canadian hacker was arrested in Quebec after a search revealed 719 Bitcoin and hundreds of thousands of Canadian dollars believed to be stolen funds
π’ Best iPhone antivirus π’
π Read
via "ITPro".
We researched the market and picked the best iPhone antivirus.π Read
via "ITPro".
IT PRO
Best iPhone antivirus | IT PRO
We researched the market and picked the best iPhone antivirus.
π’ Identity theft: What it is, and how it can affect your business π’
π Read
via "ITPro".
Discover clear identity theft definitions, and the various forms this crime can takeπ Read
via "ITPro".
IT PRO
Identity theft: What it is, and how it can affect your business | IT PRO
Discover clear identity theft definitions, and the various forms this crime can take
π’ CISA issues fresh orders to polish security vulnerability detection in federal agencies π’
π Read
via "ITPro".
The move marks the latest step in the cyber security authority's ongoing ambition to minimise the government's exposure to attacksπ Read
via "ITPro".
IT PRO
CISA issues fresh orders to polish security vulnerability detection in federal agencies | IT PRO
The move marks the latest step in the cyber security authority's ongoing ambition to minimise the government's exposure to attacks
π’ Webroot SecureAnywhere AntiVirus review π’
π Read
via "ITPro".
A compact and swift solution you wonβt even noticeπ Read
via "ITPro".
IT PRO
Webroot SecureAnywhere AntiVirus review | IT PRO
A compact and swift solution you wonβt even notice
π’ Beating the bad bots: Six ways to identify and block spam traffic π’
π Read
via "ITPro".
Not all traffic is good. Learn how to prevent bad bots from overrunning your websiteπ Read
via "ITPro".
IT PRO
Beating the bad bots: Six ways to identify and block spam traffic | IT PRO
Not all traffic is good. Learn how to prevent bad bots from overrunning your website
π’ Best business antivirus π’
π Read
via "ITPro".
To help you find the ideal antivirus platform for your company, we analyzed some of the best business antivirus platforms of todayπ Read
via "ITPro".
IT PRO
Best business antivirus | IT PRO
To help you find the ideal antivirus platform for your company, we analyzed some of the best business antivirus platforms of today
ποΈ Critical flaw in open source WebPageTest remains unpatched ποΈ
π Read
via "The Daily Swig".
Public disclosure, a talk, and a blog post later, the RCE exploit remains unresolvedπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Critical flaw in open source WebPageTest remains unpatched
Public disclosure, a talk, and a blog post later, the RCE exploit remains unresolved
βΌ CVE-2022-40824 βΌ
π Read
via "National Vulnerability Database".
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function.π Read
via "National Vulnerability Database".