Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of August 15, 2022
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of August 15, 2022

3 years ago Andrew Swoboda
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of August 15, 2022

All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of August 15th, 2022. I’ve also included some comments on these stories.

Newly Uncovered PyPI Package Drops Fileless Cryptominer to Linux Systems

A now-removed rogue package pushed to the official third-party software repository for Python has been found to deploy cryptominers on Linux systems, reports The Hacker News. The module, named “secretslib” and downloaded 93 times prior to its deletion, was released to the Python Package Index (PyPI) on August 6, 2022 and is described as “secrets matching and verification made easy.”

ANDREW SWOBODA | Senior Security Researcher at Tripwire

“secretslib” was removed from PyPi because it runs cryptominers on Linux systems in-memory. To achieve this “secretslib” pulls an ELF file from a remote server and deletes the file after it is running in memory. The package was assigned to a legitimate software engineer to build trust and have people download the library.


PoC exploit code for critical Realtek RCE flaw released online

The PoC exploit code for a critical stack-based buffer overflow issue, tracked as CVE-2022-27255 (CVSS 9.8), was recently released online. The code was for a critical vulnerability affecting networking devices using Realtek RTL819x system on a chip, notes Security Affairs.

Andrew Swoboda | Senior Security Researcher at Tripwire

Realtek RTL819x system is subject to a code execution vulnerability. This vulnerability is being tracked as CVE-2022-27255 and was discovered by researchers from Faraday Security. The vulnerability is located in the SDK for the opensource eCos operating system. The vulnerability is exploited by overflowing a buffer in the “SIP ALG” module. The module fails to check the size of the contents before data into a buffer. It is possible to exploit this vulnerability on the WAN interface by crafting arguments in SDP data or a SIP header.


Safari 15.6.1 addresses a zero-day flaw actively exploited in the wild

Apple released Safari 15.6.1 for macOS Big Sur and Catalina to address a zero-day vulnerability actively exploited in the wild, Security Affairs reports. It is being tracked as CVE-2022-32893 and was reported by an anonymous researcher. Interestingly, the same issue was also found in MacOS Monterey, iPhones and iPads.

Andrew Swoboda | Senior Security Researcher at Tripwire

Apple Safari is subject to an out-of-bounds write issue in WebKit. Apple has fixed the issue by improving the bounds checking. An attacker could execute arbitrary code upon successful exploitation of this issue. This issue might be actively exploited, and Safari should be updated to prevent exploitation.


New Amazon Ring Vulnerability Could Have Exposed All Your Camera Recordings

Retail giant Amazon patched a high-severity security issue in its Ring app for Android in May, states The Hacker News. If exploited, the vulnerability could have enabled a rogue application installed on a user’s device to access sensitive information and camera recordings.

Andrew Swoboda | Senior Security Researcher at Tripwire

Checkmarx discovered the ability to use a cross-site scripting exploit that could enable an attacker to install a malicious application. This application could then be used to obtain Authorization Token. This can then be leveraged to obtain the session cookie and the hardware ID. This would give an attacker access to the user’s account and all personal information associated with it. This issue has been patched since May 27.


Keep in Touch with Tripwire VERT

Want more insights from Tripwire VERT before our next cybersecurity news roundup comes out? Subscribe to our newsletter here.

Previous VERT Cybersecurity News Roundups

  • August 8, 2022
  • August 1, 2022
  • July 25, 2022
  • June 20, 2022
  • June 6, 2022
  • May 30, 2022
  • May 16, 2022
  • May 2, 2022
  • April 25, 2022
  • April 18, 2022

The post ” Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of August 15, 2022″ appeared first on TripWire

Source:TripWire – Andrew Swoboda

Tags: Android, Critical Severity, Exploit, Hacker, Hacker News, High Severity, Linux, TripWire, Vulnerability

Continue Reading

Previous RTLS Systems Found Vulnerable to MiTM Attacks and Location Tampering
Next Meet Borat RAT, a New Unique Triple Threat

More Stories

  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery

7 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk

8 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities

10 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach

How Samsung Knox Helps Stop Your Network Security Breach

11 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

13 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Data Breach
  • Vulnerabilities

Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries

16 hours ago [email protected] (The Hacker News)

Recent Posts

  • China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery
  • CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk
  • Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
  • How Samsung Knox Helps Stop Your Network Security Breach
  • Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT