πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-4503 β€Ό

Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Critical IP spoofing bug patched in Cacti πŸ—“οΈ

β€˜Not that hard to execute if attacker has access to a monitoring platform running Cacti’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Data Destruction Policies in the Age of Cloud Computing πŸ•΄

It's time for on-the-record answers to questions about data destruction in cloud environments. Without access, how do you verify data has been destroyed? Do processes meet DoD standards, or do we need to adjust standards to meet reality?

πŸ“– Read

via "Dark Reading".
πŸ•΄ Blackmailing MoneyMonger Malware Hides in Flutter Mobile Apps πŸ•΄

Money-lending apps built using the Flutter software development kit hide a predatory spyware threat and highlight a growing trend of using personal data for blackmail.

πŸ“– Read

via "Dark Reading".
⚠ Apple patches everything, finally reveals mystery of iOS 16.1.2 ⚠

There's an update for everything this time, not just for iOS.

πŸ“– Read

via "Naked Security".
⚠ Patch Tuesday: 0-days, RCE bugs, and a curious tale of signed malware ⚠

Tales of derring-do in the cyberunderground! (And some zero-days.)

πŸ“– Read

via "Naked Security".
⚠ S3 Ep113: Pwning the Windows kernel – the crooks who hoodwinked Microsoft [Audio + Text] ⚠

Return o' the rookit, super-sneaky wireless spyware, credit card skimming, and patches galore. Listen and learn!

πŸ“– Read

via "Naked Security".
πŸ›  Adversary3 3.0 πŸ› 

Adversary3 is a tool to navigate the vast www.malvuln.com malware vulnerability dataset.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Meta Ponies Up $300K Bounty for Zero-Click Mobile RCE Bugs in Facebook πŸ•΄

Facebook's parent company has also expanded bug-bounty payouts to include Oculus and other "metaverse" gadgets for AR/VR.

πŸ“– Read

via "Dark Reading".
πŸ•΄ WatchGuard Threat Lab Report Finds Top Threat Arriving Exclusively Over Encrypted Connections πŸ•΄

New research also analyzes the commoditization of adversary-in-the-middle attacks, JavaScript obfuscation in exploit kits, and a malware family with Gothic Panda ties.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Axonius Bolsters SaaS Management Offering With New Behavioral Analytics and SaaS User-Device Association Capabilities to Help Teams Address SaaS Application Risk πŸ•΄

New features bring greater visibility and context into SaaS applications access and activity.

πŸ“– Read

via "Dark Reading".
πŸ‘Ž1
β€Ό CVE-2022-39929 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22063 β€Ό

Memory corruption in Core due to improper configuration in boot remapper.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23474 β€Ό

Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapperÒ€ℒs innerHTML. This issue is patched in version 2.26.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20588 β€Ό

File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to run arbitrary code via avatar upload to index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36607 β€Ό

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23524 β€Ό

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the _strvals_ functions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39934 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39939 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39941 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42852 β€Ό

The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.

πŸ“– Read

via "National Vulnerability Database".