πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-41948 β€Ό

DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Affected versions are subject to a privilege escalation vulnerability. A DHIS2 user with authority to manage users can assign superuser privileges to themself by manually crafting an HTTP PUT request. Only users with the following DHIS2 user role authorities can exploit this vulnerability. Note that in many systems the only users with user admin privileges are also superusers. In these cases, the escalation vulnerability does not exist. The vulnerability is only exploitable by attackers who can authenticate as users with the user admin authority. As this is usually a small and relatively trusted set of users, exploit vectors will often be limited. DHIS2 administrators should upgrade to the following hotfix releases: 2.36.12.1, 2.37.8.1, 2.38.2.1, 2.39.0.1. The only known workaround to this issue is to avoid the assignment of the user management authority to any users until the patch has been applied.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ JSON syntax hack allowed SQL injection payloads to be smuggled past WAFs πŸ—“οΈ

Five vendors act to thwart generic hack

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-2752 β€Ό

A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Google: Use SLSA Framework for Better Software Security πŸ•΄

Security leaders also need to take a more holistic approach to addressing supply chain risks, company says in new research report.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How Naming Can Change the Game in Software Supply Chain Security πŸ•΄

A reliance on CPE names currently makes accurate searching for high-risk security vulnerabilities difficult.

πŸ“– Read

via "Dark Reading".
⚠ Credit card skimming – the long and winding road of supply chain failure ⚠

Don't keep calling home to a JavaScript server that closed its doors eight years ago!

πŸ“– Read

via "Naked Security".
πŸ•΄ Iranian APT Targets US With Drokbk Spyware via GitHub πŸ•΄

The custom malware used by the state-backed Iranian threat group Drokbk has so far flown under the radar by using GitHub as a "dead-drop resolver" to more easily evade detection.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 43 Trillion Security Data Points Illuminate Our Most Pressing Threats πŸ•΄

A new report helps companies understand an ever-changing threat landscape and how to strengthen their defenses against emerging cybersecurity trends.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-44213 β€Ό

ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4264 β€Ό

Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep112: Data breaches can haunt you more than once! [Audio + Text] ⚠

Breaches, exploits, busts, buffer overflows and bug hunting - entertaining and educational in equal measure.

πŸ“– Read

via "Naked Security".
πŸ‘1πŸ”₯1
πŸ—“οΈ ChatGPT bid for bogus crypto bug bounty is thwarted πŸ—“οΈ

Improving large language models offer β€˜just one more way to attack code, and one more way to defend code’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ 7 Ways Gaming Companies Can Battle Cybercrime on Their Platforms πŸ•΄

Balancing gameplay and security can drive down risks and improve gamers' trust and loyalty.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23479 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4170 β€Ό

The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23468 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29838 β€Ό

Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information in the case of a device reset. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23480 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3259 β€Ό

Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23483 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44838 β€Ό

Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.

πŸ“– Read

via "National Vulnerability Database".