๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2022-3458 โ€ผ

A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210559.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-2720 โ€ผ

In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3465 โ€ผ

A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of the file /index.asp. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210700.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3464 โ€ผ

A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด InterVision Announces Study Identifying Ransomware as No. 1 Threat to Business Longevity ๐Ÿ•ด

InterVision releases a new website focused on the customer experience, making B2B cybersecurity purchasing decisions easier.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-37614 โ€ผ

Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42715 โ€ผ

A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger arbitrary JavaScript code execution.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-40871 โ€ผ

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด 2 Out of 3 Companies See Zero Trust Network Access as Key to Mitigate Work-From-Anywhere Risks, According to New EMA Report ๐Ÿ•ด

Report also shows that cloud-based solutions minimize complexity to enable easy adoption by small to midsize businesses.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Cloud Data Breaches Are Running Rampant. What Are the Common Characteristics? ๐Ÿ•ด

Protecting against data breaches requires detailed analysis of recent attacks for remediation and prevention.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Vectra Advances Security AI to Deliver Attack Signal Intelligenceโ„ข, Empowering Security Teams to Investigate and Respond to Attacks in Real Time ๐Ÿ•ด

Security AI-driven Attack Signal Intelligence automates cyber threat detection, triage, and prioritization across public cloud, SaaS, identity and networks.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Beachhead Solutions Adds Windows Security Management to the BeachheadSecureยฎ Platform ๐Ÿ•ด

Included at no added cost, BeachheadSecure now provides accountwide management of Microsoft Defender AV, Firewall, and Controlled Folders for the most complete PC and device security available.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-3467 โ€ผ

A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality of the file /jsoa/hntdCustomDesktopActionContent. The manipulation of the argument inforid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-210709 was assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-33106 โ€ผ

WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  Move over Patch Tuesday โ€“ itโ€™s Ada Lovelace Day! โš 

Hacking on actual computers is one thing, but hacking purposefully on imaginary computers is, these days, something we can only imagine.

๐Ÿ“– Read

via "Naked Security".
โš  Mystery iPhone update patches against iOS 16 mail crash-attack โš 

The problem with crashy messaging apps is that *other people* get to choose if and when to send you messages...

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด E-Commerce Losses to Online Payment Fraud to Exceed $48B Globally in 2023, as Fraud Incursions Evolve ๐Ÿ•ด

Study estimates a 16% growth in e-commerce fraud losses in just 12 months.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Cyolo Receives Investment from IBM Ventures for Zero Trust Secure Access Platform ๐Ÿ•ด

The investment by IBM Ventures enables further collaboration to accelerate the adoption of modernized, identity-based connectivity for today's digital organizations.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Key Takeaways From Omdia's IGA Market Radar ๐Ÿ•ด

Identity governance administration (IGA) started life as a tool for organizations to meet a sudden surge of legal and regulatory requirements, but๏ปฟ it has grown into a key enabler of security.

๐Ÿ“– Read

via "Dark Reading".
โš  Patch Tuesday in brief โ€“ one 0-day fixed, but no patches for Exchange! โš 

There's a zero-day patch, but it's not for the zero-day you thought.

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด Airborne Drones Are Dropping Cyber-Spy Exploits in the Wild ๐Ÿ•ด

Drone-based cyberattacks to spy on corporate targets are no longer hypothetical, one incident from this summer shows.

๐Ÿ“– Read

via "Dark Reading".