πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ The sooner the FIDO Alliance can shut down passwords, the better πŸ“’

Passwords aren’t going anywhere, but that hasn’t stopped the dream of a passwordless future – and it seems that Apple, Google and Microsoft agree

πŸ“– Read

via "ITPro".
πŸ“’ UK outsourcer Interserve fined Β£4.4 million for litany of data protection failings πŸ“’

The numerous security blunders allowed cyber attackers to comprise its systems, install malware, and access the personal data of 113,000 of its staff

πŸ“– Read

via "ITPro".
πŸ“’ The future of work is already here. Now’s the time to secure it. πŸ“’

Robust security to protect and enable your business

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ Australia to increase maximum data breach penalty to $50 million πŸ“’

The country's government is looking to raise the maximum fine from $2 million AUD and introduce new legislation to handle cyber attacks better

πŸ“– Read

via "ITPro".
⚠ When cops hack back: Dutch police fleece DEADBOLT criminals (legally!) ⚠

Crooks: Show us the money! Cops: How about you show us the decryption keys first?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-44769 β€Ό

An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Denial-of-Service (DoS) condition which can only be reverted via a factory reset. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44776 β€Ό

A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbitrarily change the security access rights to KVM and Virtual Media functionalities. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26731 β€Ό

Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45925 β€Ό

Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42010 β€Ό

Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38117 β€Ό

Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt usersÒ€ℒ ciphertext and tamper with it.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39314 β€Ό

Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication Attempts. This vulnerability affects you only if you are using the `code` or `password-reset` auth method with the `auth.methods` option or if you have enabled the `debug` option in production. By using two or more IP addresses and multiple login attempts, valid user accounts will lock, but invalid accounts will not, leading to account enumeration. This issue has been patched in versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1. If you cannot update immediately, you can work around the issue by setting the `auth.methods` option to `password`, which disables the code-based login and password reset forms.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46279 β€Ό

Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attacks against users. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36368 β€Ό

Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41799 β€Ό

Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26732 β€Ό

A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network configuration of the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43680 β€Ό

In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41797 β€Ό

Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39313 β€Ό

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.17, and prior to 5.2.8 on the 5.x branch, crash when a file download request is received with an invalid byte range, resulting in a Denial of Service. This issue has been patched in versions 4.10.17, and 5.2.8. There are no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41986 β€Ό

Information disclosure vulnerability in Android App 'IIJ SmartKey' versions prior to 2.1.4 allows an attacker to obtain a one-time password issued by the product under certain conditions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26729 β€Ό

Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".