πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Slippery RansomExx Malware Moves to Rust, Evading VirusTotal πŸ•΄

A new, harder-to-peg version of the ransomware has been rewritten in the Rust programming language.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep110: Spotlight on cyberthreats – an expert speaks [Audio + Text] ⚠

Latest episode - security expert John Shier explains what the real-life cybercrime stories in the Sophos Threat Report can teach us

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-38767 β€Ό

An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-45040 β€Ό

A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45039 β€Ό

An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-45037 β€Ό

A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44411 β€Ό

Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via a bruteforce attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38377 β€Ό

An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38166 β€Ό

In F?Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45038 β€Ό

A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45036 β€Ό

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37720 β€Ό

Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.

πŸ“– Read

via "National Vulnerability Database".
⚠ Voice-scamming site β€œiSpoof” seized, 100s arrested in massive crackdown ⚠

Those numbers or names that pop up when a call comes up? They're OK as a hint of who's calling, but THEY PROVE NOTHING

πŸ“– Read

via "Naked Security".
πŸ‘1
β€Ό CVE-2022-44858 β€Ό

Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45208 β€Ό

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41705 β€Ό

Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45210 β€Ό

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45206 β€Ό

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45476 β€Ό

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application is vulnerable to CSRF, processes uploaded files server-side (instead of just returning them for download), and allows unauthenticated users to access uploaded files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45207 β€Ό

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23044 β€Ό

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application is vulnerable to CSRF, processes uploaded files server-side (instead of just returning them for download), and allows unauthenticated users to access uploaded files.

πŸ“– Read

via "National Vulnerability Database".