πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Zerobot Weaponizes Numerous Flaws in Slew of IoT Devices πŸ•΄

The botnet exploits flaws in various routers, firewalls, network-attached storage, webcams, and other products and allows attackers to take over affected systems.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-45217 β€Ό

A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cybersecurity Resilience Emerges as Top Priority as 62% of Companies Say Security Incidents Impacted Business Operations πŸ•΄

Cisco's annual Security Outcomes Report shows executive support for a security culture is growing. It identifies the top seven success factors that boost enterprise security resilience, with a focus on cultural, environmental, and solution-based factors that businesses leverage to achieve security.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 3 xIoT Attacks Companies Aren't Prepared For πŸ•΄

A world of increasingly connected devices has created a vast attack surface for sophisticated adversaries.

πŸ“– Read

via "Dark Reading".
πŸ•΄ San Francisco Rolls Back Its Plan for Killer Robots πŸ•΄

After an uproar, the city board voted to rescind last week's bill to allow police to use robots to deliver deadly force. The fight isn't over, but there's a good reason it should be.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Black Hat Europe 2022: A defendable internet is possible, but only with industry makeover πŸ—“οΈ

Empower buyers and stop fixating about zero-days, conference attendees told

πŸ“– Read

via "The Daily Swig".
πŸ‘Ž1
πŸ•΄ Piiano Equips Developers to Stop Sensitive Data Breaches πŸ•΄

Data protection company Piiano officially launches a vault for sensitive customer data, the first among a suite of privacy tools for developers.

πŸ“– Read

via "Dark Reading".
⚠ SIM swapper sent to prison for 2FA cryptocurrency heist of over $20m ⚠

Guilty party got 18 months, also has to pay back $20m he probably hasn't got, which could land him in more hot water.

πŸ“– Read

via "Naked Security".
🀯1
πŸ•΄ Will New CISA Guidelines Help Bolster Cyber Defenses? πŸ•΄

Learn how BOD 23-01 asset inventory mandates can help all organizations tighten cybersecurity.

πŸ“– Read

via "Dark Reading".
πŸ”₯1
β€Ό CVE-2020-36565 β€Ό

Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41720 β€Ό

On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS("C:/tmp").Open("COM1") opens the COM1 device. Both os.DirFS and http.Dir only provide read-only filesystem access. In addition, on Windows, an os.DirFS for the directory (the root of the current drive) can permit a maliciously crafted path to escape from the drive and access any path on the system. With fix applied, the behavior of os.DirFS("") has changed. Previously, an empty root was treated equivalently to "/", so os.DirFS("").Open("tmp") would open the path "/tmp". This now returns an error.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43581 β€Ό

IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44393 β€Ό

Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-41735 β€Ό

IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 65687.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44361 β€Ό

An issue was discovered in ZZCMS 2022. There is a cross-site scripting (XSS) vulnerability in admin/ad_list.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44371 β€Ό

hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 4 Arrested for Filing Fake Tax Returns With Stolen Data πŸ•΄

Cybercrooks allegedly stole personal data, used it to file IRS tax documents, and routed refunds to bank accounts under their control.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-45550 β€Ό

AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46770 β€Ό

qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44373 β€Ό

A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1.01.B01) which may result in remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44351 β€Ό

Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.

πŸ“– Read

via "National Vulnerability Database".