πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-41833 β€Ό

In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Customer Data Exposed by Misconfigured Server πŸ•΄

The data exposure was the result of an "unintentional misconfiguration on an endpoint" and not a security vulnerability, Microsoft said.

πŸ“– Read

via "Dark Reading".
🀯2πŸ€”1
β€Ό CVE-2022-3327 β€Ό

Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41358 β€Ό

A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37598 β€Ό

Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33231 β€Ό

Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbitrary code via the notes field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-12744 β€Ό

The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26954 β€Ό

Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync function, (3) SuccessfulAuthentication method, or (4) NopRedirectResultExecutor class.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37298 β€Ό

Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring server.

πŸ“– Read

via "National Vulnerability Database".
⚠ Women in Cryptology – USPS celebrates WW2 codebreakers ⚠

What did you do in the war, Mom? Oh, y'know, a bit of this and that...

πŸ“– Read

via "Naked Security".
πŸ•΄ 8 Trends Driving Cybersecurity in the Public Sector πŸ•΄

CISOs and security leaders in state and local governments are dealing with increasing threats like ransomware β€” with varying degrees of cyber maturity.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Bolster Deepens Platform with Dark Web Threat Intelligence and 24/7 Support πŸ•΄

Bolster delivers intelligence and remediation across web, social media, app stores, and Dark Web, with 24/7, live SOC support.

πŸ“– Read

via "Dark Reading".
πŸ•΄ HP Launches Sure Access Enterprise to Protect High Value Data and Systems πŸ•΄

HP enhances HP Wolf Security portfolio to stop attackers hijacking privileged access to sensitive data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-42197 β€Ό

In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42201 β€Ό

Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42200 β€Ό

Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31366 β€Ό

An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42198 β€Ό

In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42199 β€Ό

Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Datadog Launches Cloud Security Management to Provide Cloud Native Application Protection πŸ•΄

Product brings together workload and infrastructure security into a single platform to provide a unified approach to protecting cloud environments.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CyCognito Launches Next Generation of Exploit Intelligence Threat Remediation Platform πŸ•΄

External attack surface management leader unveils evolution of risk intelligence solution, including a virtual sandbox environment to safely validate steps to remediation.

πŸ“– Read

via "Dark Reading".