πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-48300 β€Ό

The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48296 β€Ό

The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48294 β€Ό

The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22603 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48299 β€Ό

The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22609 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41064 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48298 β€Ό

The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22607 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48297 β€Ό

The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48288 β€Ό

The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48286 β€Ό

The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0575 β€Ό

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Phishing Surges Ahead, as ChatGPT & AI Loom πŸ•΄

AI and phishing-as-a-service (PaaS) kits are making it easier for threat actors to create malicious email campaigns, which continue to target high-volume applications using popular brand names.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cryptographers Decode Secret Letters of Mary, Queen of Scots πŸ•΄

Nearly a half-millennium after her execution, encrypted letters from the imprisoned royal offer a fascinating look into early cryptography.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Kaspersky Finds Growing Number of Parents Experiencing Ransomware Attacks on Children's Schools πŸ•΄

Schools paying higher ransoms and seeing longer closures, according to survey of parents.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ U.S., U.K. Sanction 7 Men Tied to Trickbot Hacking Group β™ŸοΈ

Authorities in the United States and United Kingdom today levied financial sanctions against seven men accused of operating "Trickbot," a cybercrime-as-a-service platform based in Russia that has enabled countless ransomware attacks and bank account takeovers since its debut in 2016. The U.S. Department of the Treasury says the Trickbot group is associated with Russian intelligence services, and that this alliance led to the targeting of many U.S. companies and government entities.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ 7 Critical Cloud Threats Facing the Enterprise in 2023 πŸ•΄

From shadow data to misconfigurations, and overpermissioning to multicloud sprawl, Dark Reading's cloud security slideshow helps security pros understand the threat horizon.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Avast Threat Report: Consumers Plagued With Refund Fraud, Tech Support Scams, and Adware πŸ•΄

Avast researchers also discovered and reported two zero-day vulnerabilities, and observed the spread of information-stealing malware, remote access trojans, and botnets.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-21435 β€Ό

Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.

πŸ“– Read

via "National Vulnerability Database".