February 24, 2022 at 08:05PM

■■■■■ CISA Alerts on Actively Exploited Flaws in Zabbix; an open-source Network Monitoring Platform. ︎CVE-2022-23131: Zabbix Frontend Authentication Bypass Vulnerability. ︎CVE-2022-23134: Zabbix Frontend Improper Access Control Vulnerability. https://www.cisa.gov/uscert/ncas/current-activity/2022/02/22/cisa-adds-two-known-exploited-vulnerabilities-catalog https://thehackernews.com/2022/02/cisa-alerts-on-actively-exploited-flaws.html https://t.me/cKure/10784

February 24, 2022 at 06:22PM

■■■■□ Zero-day XSS vulnerability in Horde webmail client can be triggered by file preview function. https://portswigger.net/daily-swig/zero-day-xss-vulnerability-in-horde-webmail-client-can-be-triggered-by-file-preview-function https://t.me/cKure/10783

February 24, 2022 at 04:12PM

■■■■■ Israel : Samsung shipped an estimated 100 million smartphones with botched encryption, including models ranging from the 2017 Galaxy S8 on up to last year’s Galaxy S21. Researchers at Tel Aviv University found what they called “severe” cryptographic design flaws that could have let attackers siphon the devices’ hardware-based cryptographic keys: keys that unlock…