βΌ CVE-2022-39863 βΌ
π Read
via "National Vulnerability Database".
Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permission.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39867 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39859 βΌ
π Read
via "National Vulnerability Database".
Implicit intent hijacking vulnerability in UPHelper library prior to version 3.0.12 allows attackers to access sensitive information via implicit intent.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39877 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39860 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive information via implicit broadcast.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39850 βΌ
π Read
via "National Vulnerability Database".
Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39870 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39875 βΌ
π Read
via "National Vulnerability Database".
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39864 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39856 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call information.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36868 βΌ
π Read
via "National Vulnerability Database".
Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39866 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39871 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39878 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via implicit intent broadcast.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39868 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39872 βΌ
π Read
via "National Vulnerability Database".
Improper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39874 βΌ
π Read
via "National Vulnerability Database".
Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.π Read
via "National Vulnerability Database".
π΄ LofyGang Uses 100s of Malicious NPM Packages to Poison Open Source Software π΄
π Read
via "Dark Reading".
The group has been operating for over a year, promoting their tools in hacking forums, stealing credit card information, and using typosquatting techniques to target open source software flaws.π Read
via "Dark Reading".
Dark Reading
LofyGang Uses 100s of Malicious NPM Packages to Poison Open Source Software
The group has been operating for over a year, promoting their tools in hacking forums, stealing credit card information, and using typosquatting techniques to target open source software flaws.
β WhatsApp goes after Chinese password scammers via US court β
π Read
via "Naked Security".
If you can't beat 'em, sue 'em!π Read
via "Naked Security".
Naked Security
WhatsApp goes after Chinese password scammers via US court
If you canβt beat βem, sue βem!
π΄ Patch Now: Fortinet FortiGate & FortiProxy Contain Critical Vuln π΄
π Read
via "Dark Reading".
Fortinet issued a customer advisory urging customers to apply its update immediately.π Read
via "Dark Reading".
Dark Reading
Patch Now: Fortinet FortiGate & FortiProxy Contain Critical Vuln
The bug is under active exploitation; Fortinet issued a customer advisory urging customers to apply its update immediately.
π΄ State Bar of Georgia Notifies Members and Employees of Cybersecurity Incident π΄
π Read
via "Dark Reading".
Current and former employees and members are being offered complimentary credit monitoring and identity protection services as some personal information may have been accessed.π Read
via "Dark Reading".
Darkreading
State Bar of Georgia Notifies Members and Employees of Cybersecurity Incident
<p>Current and former employees and members are being offered complimentary credit monitoring and
identity protection services as some personal information may have been accessed.</p>
identity protection services as some personal information may have been accessed.</p>