πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Devs urged to rotate secrets after CircleCI suffers security breach πŸ—“οΈ

DevOps platform advises customers to revoke API tokens

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2015-10014 β€Ό

A vulnerability classified as critical has been found in arekk uke. This affects an unknown part of the file lib/uke/finder.rb. The manipulation leads to sql injection. The name of the patch is 52fd3b2d0bc16227ef57b7b98a3658bb67c1833f. It is recommended to apply a patch to fix this issue. The identifier VDB-217485 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45995 β€Ό

There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not to restart or even execute arbitrary code. It is a different vulnerability from CVE-2022-2414.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2014-125040 β€Ό

A vulnerability was found in stevejagodzinski DevNewsAggregator. It has been rated as critical. Affected by this issue is the function getByName of the file php/data_access/RemoteHtmlContentDataAccess.php. The manipulation of the argument name leads to sql injection. The name of the patch is b9de907e7a8c9ca9d75295da675e58c5bf06b172. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217484.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How to Ensure Cybersecurity Investments Remain a Priority Across Your Organization πŸ•΄

Collaboration across all business units is key to building a robust cybersecurity program.

πŸ“– Read

via "Dark Reading".
πŸ›  SimpleRmiDiscoverer 0.1 πŸ› 

SimpleRmiDiscoverer is a JMX RMI scanning tool for unsecured (without enabled authentication) instances of JAVA JMX. It does not use standard Java RMI/JMX classes like other available tools but rather communicates directly over TCP. The tool is written in Java and is very useful in red teaming operations because JVM is still ubiquitous in corporate environments. It can be executed by unprivileged (non-admin) users.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Faraday 4.3.2 πŸ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Threat Actors Evade Detection Through Geofencing & Fingerprinting πŸ•΄

Security teams may be missing targeted attacks and advanced exploits if attackers are using evasive techniques to avoid detection. Defenders need to up their game.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Tesla tackles CORS misconfigurations that left internal networks vulnerable πŸ—“οΈ

Typosquatting ploy successfully bypassed firewalls of multiple organizations

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-47091 β€Ό

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47653 β€Ό

GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46489 β€Ό

GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the gf_isom_box_parse_ex function at box_funcs.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47659 β€Ό

GPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_data

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47662 β€Ό

GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample isomedia/media.c:662

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47654 β€Ό

GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8261

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46490 β€Ό

GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the afrt_box_read function at box_code_adobe.c.

πŸ“– Read

via "National Vulnerability Database".