Artwork

Paul Torgersen द्वारा प्रदान की गई सामग्री. एपिसोड, ग्राफिक्स और पॉडकास्ट विवरण सहित सभी पॉडकास्ट सामग्री Paul Torgersen या उनके पॉडकास्ट प्लेटफ़ॉर्म पार्टनर द्वारा सीधे अपलोड और प्रदान की जाती है। यदि आपको लगता है कि कोई आपकी अनुमति के बिना आपके कॉपीराइट किए गए कार्य का उपयोग कर रहा है, तो आप यहां बताई गई प्रक्रिया का पालन कर सकते हैं https://hi.player.fm/legal
Player FM - पॉडकास्ट ऐप
Player FM ऐप के साथ ऑफ़लाइन जाएं!

Android Photo Overshare, Linux PWNkit, UnRAR Vuln, and more.

3:14
 
साझा करें
 

संग्रहीत श्रृंखला ("निष्क्रिय फ़ीड" status)

When? This feed was archived on May 25, 2023 16:09 (11M ago). Last successful fetch was on July 29, 2022 18:35 (1+ y ago)

Why? निष्क्रिय फ़ीड status. हमारे सर्वर निरंतर अवधि के लिए एक वैध डिजिटल ऑडियो फ़ाइल फ़ीड पुनर्प्राप्त करने में असमर्थ थे।

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 332943559 series 2478053
Paul Torgersen द्वारा प्रदान की गई सामग्री. एपिसोड, ग्राफिक्स और पॉडकास्ट विवरण सहित सभी पॉडकास्ट सामग्री Paul Torgersen या उनके पॉडकास्ट प्लेटफ़ॉर्म पार्टनर द्वारा सीधे अपलोड और प्रदान की जाती है। यदि आपको लगता है कि कोई आपकी अनुमति के बिना आपके कॉपीराइट किए गए कार्य का उपयोग कर रहा है, तो आप यहां बताई गई प्रक्रिया का पालन कर सकते हैं https://hi.player.fm/legal
A daily look at the relevant information security news from overnight - 29 June, 2022
Episode 254 - 29 June 2022
Android Photo Overshare- https://www.bleepingcomputer.com/news/security/amazon-fixes-high-severity-vulnerability-in-android-photos-app/
Linux PWNkit -
https://www.securityweek.com/cisa-says-pwnkit-linux-vulnerability-exploited-attacks
Service Fabric Fix- https://www.bleepingcomputer.com/news/security/microsoft-fixes-bug-that-let-hackers-hijack-azure-linux-clusters/
Firefox 102 -
https://www.securityweek.com/firefox-102-patches-19-vulnerabilities-improves-privacy
UnRAR Vuln -
https://thehackernews.com/2022/06/new-unrar-vulnerability-could-let.html
Hi, I’m Paul Torgersen. It’s Wednesday June 29th, 2022, and this is a look at the information security news from overnight.
From BleepingComputer.com
Amazon has fixed a vulnerability in its Photos app for Android, which has over 50 million downloads on the Google Play Store. The image and video storage app enables users to share files with up to five family members. Unfortunately, if the flaw is exploited, it also shares access tokens for Amazon API authentication with the bad guys.
From SecurityWeek.com:
The CISA says a Linux vulnerability known as PwnKit has been exploited in the wild. The flaw is a memory corruption issue that affects Polkit, a component designed for controlling system-wide privileges in Unix-like operating systems. Proof-of-concepts are available and exploitation is easy, which is why the CISA has added the vulnerability to its must patch list. Government orgs have until July 18 to install patches, but you private orgs should really get your patch on too.
From BleepingComputer.com:
Microsoft has fixed a container escape vulnerability in the Service Fabric application hosting platform. Exploitation could allow threat actors to escalate privileges to root, gain control of the host node, and compromise the entire SF Linux cluster. According to Microsoft, Service Fabric hosts over a million apps and powers many of their Azure products, as well as others. Not only should you get your patch on, but Microsoft recommends that customers continue to review all containerized workloads (both Linux and Windows) which are permitted access to their host clusters.
From SecurityWeek.com:
Mozilla has launched Firefox 102 that includes patches for 19 vulnerabilities, including four high-severity bugs. The new version also improves user privacy by mitigating query parameter tracking when navigating the internet with Enhanced Tracking Protection in strict mode. This confines cookies to the sites that created them, preventing cross-site tracking
And last today, from TheHackerNews.com
A new security vulnerability has been disclosed in RARlab's UnRAR utility that could permit a remote attacker to execute arbitrary code on a system that relies on the binary. The flaw relates to a path traversal vulnerability in the Unix versions of UnRAR that can be triggered upon extracting a maliciously crafted RAR archive. Other versions of the software, including those for Windows and Android, are not impacted. Any software that utilizes an unpatched version of UnRAR to extract untrusted archives is affected by the flaw.
That’s all for me today. Have a great rest of your day. Like and subscribe, and until tomorrow, be safe out there.
  continue reading

221 एपिसोडस

Artwork
iconसाझा करें
 

संग्रहीत श्रृंखला ("निष्क्रिय फ़ीड" status)

When? This feed was archived on May 25, 2023 16:09 (11M ago). Last successful fetch was on July 29, 2022 18:35 (1+ y ago)

Why? निष्क्रिय फ़ीड status. हमारे सर्वर निरंतर अवधि के लिए एक वैध डिजिटल ऑडियो फ़ाइल फ़ीड पुनर्प्राप्त करने में असमर्थ थे।

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 332943559 series 2478053
Paul Torgersen द्वारा प्रदान की गई सामग्री. एपिसोड, ग्राफिक्स और पॉडकास्ट विवरण सहित सभी पॉडकास्ट सामग्री Paul Torgersen या उनके पॉडकास्ट प्लेटफ़ॉर्म पार्टनर द्वारा सीधे अपलोड और प्रदान की जाती है। यदि आपको लगता है कि कोई आपकी अनुमति के बिना आपके कॉपीराइट किए गए कार्य का उपयोग कर रहा है, तो आप यहां बताई गई प्रक्रिया का पालन कर सकते हैं https://hi.player.fm/legal
A daily look at the relevant information security news from overnight - 29 June, 2022
Episode 254 - 29 June 2022
Android Photo Overshare- https://www.bleepingcomputer.com/news/security/amazon-fixes-high-severity-vulnerability-in-android-photos-app/
Linux PWNkit -
https://www.securityweek.com/cisa-says-pwnkit-linux-vulnerability-exploited-attacks
Service Fabric Fix- https://www.bleepingcomputer.com/news/security/microsoft-fixes-bug-that-let-hackers-hijack-azure-linux-clusters/
Firefox 102 -
https://www.securityweek.com/firefox-102-patches-19-vulnerabilities-improves-privacy
UnRAR Vuln -
https://thehackernews.com/2022/06/new-unrar-vulnerability-could-let.html
Hi, I’m Paul Torgersen. It’s Wednesday June 29th, 2022, and this is a look at the information security news from overnight.
From BleepingComputer.com
Amazon has fixed a vulnerability in its Photos app for Android, which has over 50 million downloads on the Google Play Store. The image and video storage app enables users to share files with up to five family members. Unfortunately, if the flaw is exploited, it also shares access tokens for Amazon API authentication with the bad guys.
From SecurityWeek.com:
The CISA says a Linux vulnerability known as PwnKit has been exploited in the wild. The flaw is a memory corruption issue that affects Polkit, a component designed for controlling system-wide privileges in Unix-like operating systems. Proof-of-concepts are available and exploitation is easy, which is why the CISA has added the vulnerability to its must patch list. Government orgs have until July 18 to install patches, but you private orgs should really get your patch on too.
From BleepingComputer.com:
Microsoft has fixed a container escape vulnerability in the Service Fabric application hosting platform. Exploitation could allow threat actors to escalate privileges to root, gain control of the host node, and compromise the entire SF Linux cluster. According to Microsoft, Service Fabric hosts over a million apps and powers many of their Azure products, as well as others. Not only should you get your patch on, but Microsoft recommends that customers continue to review all containerized workloads (both Linux and Windows) which are permitted access to their host clusters.
From SecurityWeek.com:
Mozilla has launched Firefox 102 that includes patches for 19 vulnerabilities, including four high-severity bugs. The new version also improves user privacy by mitigating query parameter tracking when navigating the internet with Enhanced Tracking Protection in strict mode. This confines cookies to the sites that created them, preventing cross-site tracking
And last today, from TheHackerNews.com
A new security vulnerability has been disclosed in RARlab's UnRAR utility that could permit a remote attacker to execute arbitrary code on a system that relies on the binary. The flaw relates to a path traversal vulnerability in the Unix versions of UnRAR that can be triggered upon extracting a maliciously crafted RAR archive. Other versions of the software, including those for Windows and Android, are not impacted. Any software that utilizes an unpatched version of UnRAR to extract untrusted archives is affected by the flaw.
That’s all for me today. Have a great rest of your day. Like and subscribe, and until tomorrow, be safe out there.
  continue reading

221 एपिसोडस

सभी एपिसोड

×
 
Loading …

प्लेयर एफएम में आपका स्वागत है!

प्लेयर एफएम वेब को स्कैन कर रहा है उच्च गुणवत्ता वाले पॉडकास्ट आप के आनंद लेंने के लिए अभी। यह सबसे अच्छा पॉडकास्ट एप्प है और यह Android, iPhone और वेब पर काम करता है। उपकरणों में सदस्यता को सिंक करने के लिए साइनअप करें।

 

त्वरित संदर्भ मार्गदर्शिका