πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Iranian APT Targets US With Drokbk Spyware via GitHub πŸ•΄

The custom malware used by the state-backed Iranian threat group Drokbk has so far flown under the radar by using GitHub as a "dead-drop resolver" to more easily evade detection.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 43 Trillion Security Data Points Illuminate Our Most Pressing Threats πŸ•΄

A new report helps companies understand an ever-changing threat landscape and how to strengthen their defenses against emerging cybersecurity trends.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-44213 β€Ό

ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4264 β€Ό

Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep112: Data breaches can haunt you more than once! [Audio + Text] ⚠

Breaches, exploits, busts, buffer overflows and bug hunting - entertaining and educational in equal measure.

πŸ“– Read

via "Naked Security".
πŸ‘1πŸ”₯1
πŸ—“οΈ ChatGPT bid for bogus crypto bug bounty is thwarted πŸ—“οΈ

Improving large language models offer β€˜just one more way to attack code, and one more way to defend code’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ 7 Ways Gaming Companies Can Battle Cybercrime on Their Platforms πŸ•΄

Balancing gameplay and security can drive down risks and improve gamers' trust and loyalty.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23479 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4170 β€Ό

The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23468 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29838 β€Ό

Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information in the case of a device reset. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23480 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3259 β€Ό

Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23483 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44838 β€Ό

Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23484 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4336 β€Ό

In BAOTA linux panel there exists a stored xss vulnerability attackers can use to obtain sensitive information via the log analysis feature.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23478 β€Ό

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25630 β€Ό

An authenticated user can embed malicious content with XSS into the admin group policy page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3724 β€Ό

Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29839 β€Ό

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

πŸ“– Read

via "National Vulnerability Database".