πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-42893 β€Ό

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the websiteÒ€ℒs application pool.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42732 β€Ό

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the websiteÒ€ℒs application pool.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4053 β€Ό

A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213846 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41920 β€Ό

Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package to unzip files. This issue has been addressed and a fix will be included in versions 2.1.10 and 1.3.4. Users are advised to upgrade. There are no known workarounds for this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44402 β€Ό

Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42891 β€Ό

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the websiteÒ€ℒs application pool.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42894 β€Ό

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Request Forgery (SSRF) vulnerability was identified in one of the web services exposed on the syngo Dynamics application that could allow for the leaking of NTLM credentials as well as local service enumeration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44384 β€Ό

An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40751 β€Ό

IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches. IBM X-Force ID: 236601.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Iranian APT Actors Breached a US Government Network πŸ•΄

CISA says Federal Civilian Executive Branch systems were compromised through a Log4Shell vulnerability in an unpatched VMware Horizon server.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-43142 β€Ό

A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Hundreds of thousands of Emotet attacks spotted daily after four-month hiatus πŸ“’

The botnet that refuses to die returns again and is equipped with new payloads and tactics to evade detection

πŸ“– Read

via "ITPro".
πŸ“’ Enabling secure hybrid learning in schools πŸ“’

The importance of creating security awareness among key players

πŸ“– Read

via "ITPro".
πŸ“’ Google agrees record $391.5m settlement in US digital tracking case πŸ“’

The sum represents the largest settlement ever paid in a US digital privacy case which dates back to 2018

πŸ“– Read

via "ITPro".
πŸ“’ The top 12 password-cracking techniques used by hackers πŸ“’

Some of the most common, and most effective methods for stealing passwords

πŸ“– Read

via "ITPro".
πŸ“’ NSA: Phase out memory-unsafe languages like C and C++ πŸ“’

The US agency advises organisations to begin using languages like Rust, Java, and Swift

πŸ“– Read

via "ITPro".
πŸ“’ How to react to a data breach πŸ“’

Every business should have a data breach response plan, but when building one it can be difficult to know where to start

πŸ“– Read

via "ITPro".
πŸ“’ Australia considers ransomware payment ban, additional Medibank files leaked πŸ“’

REvil has claimed responsibility for the attack amidst continued refusal by Medibank to pay the ransom

πŸ“– Read

via "ITPro".
πŸ“’ How to reduce cyber security costs for your business πŸ“’

Nothing is off the table in a recession, but businesses must be careful to reduce cyber security costs without compromising on safety

πŸ“– Read

via "ITPro".
πŸ“’ What is a router and how does it work? πŸ“’

The role of a router in networking goes beyond simply allowing your business to access the web and stay connected with colleagues

πŸ“– Read

via "ITPro".
πŸ“’ Ransomware: Why do businesses still pay up? πŸ“’

Despite the guidance and best practice, an alarming proportion of businesses hit with ransomware simply pay to make it go away

πŸ“– Read

via "ITPro".