πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Microsoft Office Online Server open to SSRF-to-RCE exploit πŸ—“οΈ

Behavior functioning as intended, Microsoft reportedly says, and offers mitigation advice instead

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-42176 β€Ό

In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40084 β€Ό

OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42021 β€Ό

Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep105: WONTFIX! The MS Office cryptofail that β€œisn’t a security flaw” [Audio + Text] ⚠

The coolest video game ever! And lots of solid cybersecurity advice - listen now!

πŸ“– Read

via "Naked Security".
πŸ‘1
πŸ•΄ Name That Toon: Witching Hour πŸ•΄

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 'FurBall' Spyware Being Used Against Iranian Citizens πŸ•΄

New Android malware variant is part of long-running Domestic Kitten campaign being conducted by APT C-50 Group, analysts report.

πŸ“– Read

via "Dark Reading".
πŸ‘2
β€Ό CVE-2020-9285 β€Ό

Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42344 β€Ό

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve information exposure and privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2069 β€Ό

The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3577 β€Ό

An out-of-bounds memory write flaw was found in the Linux kernelÒ€ℒs Kid-friendly Wired Controller driver. This flaw allows a local user to crash or potentially escalate their privileges on the system. It is in bigben_probe of drivers/hid/hid-bigbenff.c. The reason is incorrect assumption - bigben devices all have inputs. However, malicious devices can break this assumption, leaking to out-of-bound write.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42233 β€Ό

Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 4 Ways To Achieve Comprehensive Security πŸ•΄

Zero trust protects identities, endpoints, applications, networks, infrastructure, and data, and can be implemented in different ways.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Battle with Bots Prompts Mass Purge of Amazon, Apple Employee Accounts on LinkedIn β™ŸοΈ

On October 10, 2022, there were 576,562 LinkedIn accounts that listed their current employer as Apple Inc. The next day, half of those profiles no longer existed. A similarly dramatic drop in the number of LinkedIn profiles claiming employment at Amazon comes as LinkedIn is struggling to combat a significant uptick in the creation of fake employee accounts that pair AI-generated profile photos with text lifted from legitimate users.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Brazilian Police Nab Suspected Member of Lapsus$ Group πŸ•΄

Lapsus$ Group became a top target after it breached the Brazilian Ministry of Health, among other targets.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Hardware Makers Standardize Server Chip Security With Caliptra πŸ•΄

The new open source specification from Open Compute Project is backed by Google, Nvidia, Microsoft, and AMD.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-3623 β€Ό

A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function follow_page_pte of the file mm/gup.c of the component BPF. The manipulation leads to race condition. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211921 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37453 β€Ό

An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3621 β€Ό

A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipulation leads to null pointer dereference. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211920.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39823 β€Ό

An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the server limit on continuation points may cause a use-after-free error

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36958 β€Ό

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".