Threat Roundup for September 30 to October 7

[![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDbBfe7re3_GTXSXxhXHE2wNeKNUPJ-Odym2Hj407JIEsoqhaRncqbWWVdFGF8HVFeuFf-9tRYJTDr5Yv3KtHFWHwNNCw0SfBhK253m7gw8NPS3_tw9byysNDzJXeSV6PpKRjM8Z ...

Continue Reading
Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API

In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.Read More ...

Continue Reading

CVSS3 - HIGH

CVE-2022-39289

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, mo ...

Continue Reading
Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API

In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.Read More ...

Continue Reading
Heimdal Kerbos vulnerable to remotely triggered NULL pointer dereference

### Overview The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can ...

Continue Reading
CVE-2022-39862

Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.Read More ...

Continue Reading
Cloudfox – Automating Situational Awareness For Cloud Penetration Tests

[![](https://blogger.googleusercontent.com/img/a/AVvXsEjnZV68nlgZG7KiqYaVB3-ucQJOspZ0Lytex_Ql7bXxJucf-OYBMvdAEj-kMSQW-Xs__geqyStu4k1cv5TlsEgYrNPFSHK3oOXURLjMAe25we1Gz0tXiMAfN9W6WgspIwGj2Kld8Q0vPP3g-JB ...

Continue Reading
CVE-2022-41672

In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: