๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด Yakima Neighborhood Health Services Notice of Data Security Incident ๐Ÿ•ด

.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Red Canary Provides First-Ever MITRE Engenuityโ„ข ATT&CKยฎ Evaluations for Managed Services ๐Ÿ•ด

.

๐Ÿ“– Read

via "Dark Reading".
โ™Ÿ๏ธ Top Zeus Botnet Suspect โ€œTankโ€ Arrested in Geneva โ™Ÿ๏ธ

Vyacheslav โ€œTankโ€ Penchukov, the accused 40-year-old Ukrainian leader of a prolific cybercriminal group that stole tens of millions of dollars from small to mid-sized businesses in the United States and Europe, has been arrested in Switzerland, according to multiple sources.

๐Ÿ“– Read

via "Krebs on Security".
๐Ÿ—“๏ธ Zendesk Explore flaws opened the door to account pillage ๐Ÿ—“๏ธ

Patched SQLi and logical access vulnerabilities posed serious risk

๐Ÿ“– Read

via "The Daily Swig".
๐Ÿ•ด Google Forks Over $391.5M in Record-Setting US Consumer Privacy Settlement ๐Ÿ•ด

A misleading location-tracking practice ensnared the search-engine giant in massive privacy case spanning 40 states.

๐Ÿ“– Read

via "Dark Reading".
โš  โ€œGucci Masterโ€ business email scammer Hushpuppi gets 11 years โš 

Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด How Routine Pen Testing Can Reveal the Unseen Flaws in Your Cybersecurity Posture ๐Ÿ•ด

Testing is an ongoing mission, not a one-and-done fix.

๐Ÿ“– Read

via "Dark Reading".
โš  Log4Shell-like code execution hole in popular Backstage dev tool โš 

Researchers at cloud coding security company Oxeye have written up a critical bug that they recently discovered in the popular cloud development toolkit Backstage. Their report includes an explanation of how the bug works, plus proof-of-concept (PoC) code showing how to exploit it. Backstage is whatโ€™s known as a cloud developer portal โ€“ a sort [โ€ฆ]

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด Where Can Third-Party Governance and Risk Management Take Us? ๐Ÿ•ด

Part 2 in our series addressing the top 10 unanswered questions in security: How will TPGRM evolve?

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Wipermania: Malware Remains a Potent Threat, 10 Years Since 'Shamoon' ๐Ÿ•ด

An in-depth analysis of system-destroying malware families presented at Black Hat Middle East & Africa shows a growing nuance in terms of how they're deployed.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ‘2
โ€ผ CVE-2022-34313 โ€ผ

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-2450 โ€ผ

The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-40405 โ€ผ

WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3965 โ€ผ

A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213544.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-33983 โ€ผ

DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the NvmExpressLegacy driver could cause SMRAM corruption through a TOCTOU attack. This issue was discovered by Insyde engineering based on the general description provided by Intel's iSTARE group. This issue was fixed in kernel 5.2: 05.27.25, kernel 5.3: 05.36.25, kernel 5.4: 05.44.25, kernel 5.5: 05.52.25 https://www.insyde.com/security-pledge/SA-2022053

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42058 โ€ผ

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-43342 โ€ผ

A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the KPI Title text field.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42119 โ€ผ

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-20832 โ€ผ

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-43693 โ€ผ

Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-41913 โ€ผ

Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic. Members of private groups or public groups with private members can be listed by users, who can create and edit post events. This vulnerability only affects sites which have discourse post events enabled. This issue has been patched in commit `ca5ae3e7e` which will be included in future releases. Users unable to upgrade should disable the `discourse_post_event_enabled` setting to fully mitigate the issue. Also, it's possible to prevent regular users from using this vulnerability by removing all groups from the `discourse_post_event_allowed_on_groups` but note that moderators will still be able to use it.

๐Ÿ“– Read

via "National Vulnerability Database".