πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-4349 β€Ό

A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215109 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46792 β€Ό

Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36609 β€Ό

A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of the file admin.php&r=article/AdminContent/edit of the component Article Handler. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215115.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ NodeBB prototype pollution flaw could lead to account takeover πŸ—“οΈ

β€˜Not a prototype pollution vulnerability as you might normally understand it’

πŸ“– Read

via "The Daily Swig".
πŸ‘1
πŸ•΄ Where to Find the Best Open Source Security Technology πŸ•΄

A free resource, updated monthly, lists the most-popular, highly rated OSS projects.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ (ISC)Β² Recruits 110,000 People Interested in a Cybersecurity Career in Three Months πŸ•΄

Rapid adoption showcases increased interest in cyber education and training for individuals looking to enter the field while helping decrease the workforce gap.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Phishing in the Cloud: We're Gonna Need a Bigger Boat πŸ•΄

SasS security is everyone's problem.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Interpres Security Emerges from Stealth to Help Companies to Optimize Security Performance πŸ•΄

Startup raises $8.5 million in seed funding led by Ten Eleven Ventures.

πŸ“– Read

via "Dark Reading".
πŸ›  TOR Virtual Network Tunneling Tool 0.4.7.12 πŸ› 

Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs). This is the source code release.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Wireshark Analyzer 4.0.2 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2022-45509 β€Ό

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41802 β€Ό

Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39903 β€Ό

Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45523 β€Ό

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45501 β€Ό

Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39915 β€Ό

Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45511 β€Ό

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45499 β€Ό

Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39902 β€Ό

Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4364 β€Ό

A vulnerability classified as critical has been found in Teledyne FLIR AX8 up to 1.46.16. Affected is an unknown function of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-215118 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45506 β€Ό

Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.

πŸ“– Read

via "National Vulnerability Database".