πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ LastPass Cops to Massive Breach Including Customer Vault Data πŸ•΄

The follow-on attack from August's source-code breach could fuel future campaigns against LastPass customers.

πŸ“– Read

via "Dark Reading".
⚠ LastPass finally admits: They did steal your password vaults after all ⚠

The crooks now know who you are, where you live, which computers are yours... and they got those password vaults, too.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-47943 β€Ό

An issue was discovered in ksmbd in the Linux kernel before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Container Verification Bug Allows Malicious Images to Cloud Up Kubernetes πŸ•΄

A complete bypass of the Kyverno security mechanism for container image imports allows cyberattackers to completely take over a Kubernetes pod to steal data and inject malware.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-28228 β€Ό

Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-28229 β€Ό

The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47946 β€Ό

An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to crash the kernel, resulting in denial of service. finish_wait can be skipped. An attack can occur in some situations by forking a process and then quickly terminating it. NOTE: later kernel versions, such as the 5.15 longterm series, substantially changed the implementation of io_sqpoll_wait_sq.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47945 β€Ό

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23854 β€Ό

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47633 β€Ό

An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8.5. This has been fixed in 1.8.5 and mitigations are available for impacted releases.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38658 β€Ό

BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40011 β€Ό

Cross Site Scripting (XSS) vulnerability in typora through 1.38 allows remote attackers to run arbitrary code via export from editor.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22449 β€Ό

IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 224915.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45798 β€Ό

A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to delete a file. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43860 β€Ό

IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ The Guardian newspaper believes "IT incident" caused by ransomware πŸ“’

It's the second case of a major Western media organisation being targeted by a cyber attack this year

πŸ“– Read

via "ITPro".
πŸ“’ Windows 10 users encounter β€˜blue screen of death’ after latest Patch Tuesday update πŸ“’

Microsoft said it is working on a fix for the issue and has offered users a temporary workaround

πŸ“– Read

via "ITPro".
πŸ“’ The IT Pro Podcast: The 2022 that didn't happen πŸ“’

Some of the biggest predictions for this year didn't come to pass

πŸ“– Read

via "ITPro".
πŸ“’ LastPass customer password vaults stolen, targeted phishing attacks likely πŸ“’

The latest fallout from the password manager's August security nightmare will probably see attackers deploying sophisticated methods to acquire decryption information

πŸ“– Read

via "ITPro".
πŸ“’ Podcast transcript: The 2022 that didn't happen πŸ“’

Read the full transcript for this episode of the IT Pro Podcast

πŸ“– Read

via "ITPro".
πŸ“’ Linux fixes maximum-severity kernel vulnerability πŸ“’

Most businesses running SMB servers are believed to be shielded but one expert likened potential exploits to Heartbleed

πŸ“– Read

via "ITPro".