๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2022-42938 โ€ผ

A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42944 โ€ผ

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-27494 โ€ผ

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42943 โ€ผ

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-41638 โ€ผ

Auth. Stored Cross-Site Scripting (XSS) in Pop-Up Chop Chop plugin <= 2.1.7 on WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-1059 โ€ผ

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3570 โ€ผ

Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด FBI: Iranian Threat Group Likely to Target US Midterms ๐Ÿ•ด

Similar to what happened around the 2020 election, FBI warns that the Emennet Pasargad group is poised to target officials and companies with embarrassing hack-and-leak campaigns.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Google's GUAC Aims to Democratize Software Supply Chain Security Metadata ๐Ÿ•ด

Software makers and customers will be able to query graph database for information about the security and provenance of components in applications and codebases.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-3646 โ€ผ

A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211961 was assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-34439 โ€ผ

Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service and performance issue on that node.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3647 โ€ผ

A vulnerability, which was classified as problematic, was found in Redis. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The name of the patch is 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-34437 โ€ผ

Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentially exploit this vulnerability, leading to a full system compromise. This impacts compliance mode clusters.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1
โ€ผ CVE-2022-31239 โ€ผ

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this sensitive data.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-26870 โ€ผ

Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-34438 โ€ผ

Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-5355 โ€ผ

The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-39272 โ€ผ

Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Fluxรƒยขรขโ€šยฌรขโ€žยขs objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or `.spec.timeout` (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields `.spec.interval` and `.spec.timeout`, however upgrading to the latest versions is still the recommended mitigation.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1
๐Ÿ•ด Embracing the Next Generation of Business Developers ๐Ÿ•ด

Security teams that embrace low-code/no-code can change the security mindset of business users.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Nok Nok, a Global Leader in Customer Passwordless Authentication, Releases Full Support for Passkeys ๐Ÿ•ด

Nok Nok, an inventor of FIDO authentication standards, announces full support for passkeys in its S3 Authentication Suite that allows organizations to replace passwords.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Scribe Security Launches Evidence-Based Security Trust Hub ๐Ÿ•ด

Security, DevSecOps, and DevOps teams can now build transparent trust in the software they deliver or use.

๐Ÿ“– Read

via "Dark Reading".