🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 When Companies Compensate the Hackers, We All Foot the Bill 🕴

Ensuring stronger in-house defenses is integral to retaining customer loyalty.

📖 Read

via "Dark Reading".
🕴 Popular WAFs Subverted by JSON Bypass 🕴

Web application firewalls from AWS, Cloudflare, F5, Imperva, and Palo Alto Networks are vulnerable to a database attack using the popular JavaScript Object Notation (JSON) format.

📖 Read

via "Dark Reading".
🕴 What We Can't See Can Hurt Us 🕴

Visibility into every environment, including cloud, enables businesses to mitigate operating risks.

📖 Read

via "Dark Reading".
CVE-2022-43503

This CVE is not valid.

📖 Read

via "National Vulnerability Database".
CVE-2022-45119

This CVE is not valid.

📖 Read

via "National Vulnerability Database".
CVE-2022-44147

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-16891. Reason: This candidate is a reservation duplicate of CVE-2019-16891. Notes: All CVE users should reference CVE-2019-16891 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

📖 Read

via "National Vulnerability Database".
CVE-2022-45043

Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.

📖 Read

via "National Vulnerability Database".
CVE-2022-45957

ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.

📖 Read

via "National Vulnerability Database".
CVE-2022-45997

Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.

📖 Read

via "National Vulnerability Database".
CVE-2022-45956

Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.

📖 Read

via "National Vulnerability Database".
CVE-2022-45977

Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.

📖 Read

via "National Vulnerability Database".
CVE-2022-45979

Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .

📖 Read

via "National Vulnerability Database".
CVE-2022-45980

Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .

📖 Read

via "National Vulnerability Database".
CVE-2022-45996

Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.

📖 Read

via "National Vulnerability Database".
S3 Ep112: Data breaches can haunt you more than once! [Audio + Text]

Breaches, exploits, busts, buffer overflows and bug hunting - entertaining and educational in equal measure.

📖 Read

via "Naked Security".
🗓️ Black Hat Europe redux: The top web hacking talks for 2022 🗓️

Catch up on the highlights of last week’s cybersecurity conference

📖 Read

via "The Daily Swig".
👍1🔥1
Pwn2Own Toronto: 54 hacks, 63 new bugs, $1 million in bounties

That's a mean average of $15,710 per bug... and 63 fewer bugs out there for crooks and rogues to find.

📖 Read

via "Naked Security".
CVE-2022-3925

The buddybadges WordPress plugin through 1.0.0 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

📖 Read

via "National Vulnerability Database".
CVE-2022-3919

The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

📖 Read

via "National Vulnerability Database".
CVE-2022-3605

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leading to a CSV injection vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-3880

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

📖 Read

via "National Vulnerability Database".
👎1