🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2022-34426

Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vulnerability leading to unintentional access to path outside of restricted directory.

📖 Read

via "National Vulnerability Database".
CVE-2022-34427

Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthenticated attacker could exploit this vulnerability leading to modification of intended OS command execution.

📖 Read

via "National Vulnerability Database".
🕴 OT Cybersecurity Leader Paul Brager Passes Away 🕴

IT security executive led ICS/OT, IT/OT integration, and other security programs, as well as diversity and inclusion efforts in the industry.

📖 Read

via "Dark Reading".
🕴 Intel Processor UEFI Source Code Leaked 🕴

Exposed code included private key for Intel Boot Guard, meaning it can no longer be trusted, according to a researcher.

📖 Read

via "Dark Reading".
🕴 Critical Open Source vm2 Sandbox Escape Bug Affects Millions 🕴

Attackers could exploit the "Sandbreak" security bug, which has earned a 10 out of 10 on the CVSS scale, to execute a sandbox escape, achieve RCE, and run shell commands on a hosting machine.

📖 Read

via "Dark Reading".
🕴 AI and Residual Finger Heat Could Be a Password Cracker's Latest Tools 🕴

New research demonstrates the use of thermal camera images of keyboards and screens in concert with AI to correctly guess computer passwords faster and more accurately.

📖 Read

via "Dark Reading".
CVE-2022-38039

Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38037, CVE-2022-38038.

📖 Read

via "National Vulnerability Database".
🤯1
CVE-2022-38026

Windows DHCP Client Information Disclosure Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-38051

Windows Graphics Component Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37997.

📖 Read

via "National Vulnerability Database".
CVE-2022-38042

Active Directory Domain Services Elevation of Privilege Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-37997

Windows Graphics Component Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-38051.

📖 Read

via "National Vulnerability Database".
CVE-2022-41037

Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41036, CVE-2022-41038.

📖 Read

via "National Vulnerability Database".
CVE-2022-38034

Windows Workstation Service Elevation of Privilege Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-38044

Windows CD-ROM File System Driver Remote Code Execution Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-38033

Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-38050

Win32k Elevation of Privilege Vulnerability.

📖 Read

via "National Vulnerability Database".
👍1
CVE-2022-38043

Windows Security Support Provider Interface Information Disclosure Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-41032

NuGet Client Elevation of Privilege Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-41038

Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41036, CVE-2022-41037.

📖 Read

via "National Vulnerability Database".
CVE-2022-41035

Microsoft Edge (Chromium-based) Spoofing Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-40047

Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.

📖 Read

via "National Vulnerability Database".