Infosec Overnights - Daily Security News

Grails RCE Vuln, PrestaShop Skimmed, FileWave Crit Flaws, and more.


Listen Later

A daily look at the relevant information security news from overnight - 26 July, 2022

Episode 273 - 26 July 2022

Grails RCE Vuln- https://portswigger.net/daily-swig/critical-security-vulnerability-in-grails-could-lead-to-remote-code-execution

PrestaShop Skimmer -
https://thehackernews.com/2022/07/hackers-exploit-prestashop-zero-day-to.html

LinkedIn Phishing for Admins -
https://www.bleepingcomputer.com/news/security/linkedin-phishing-target-employees-managing-facebook-ad-accounts/

PolicyBazaar Breached- https://www.infosecurity-magazine.com/news/indian-insurance-policybazaar/

FileWave Crit Flaws -
https://thehackernews.com/2022/07/critical-filewave-mdm-flaws-open.html

Hi, I’m Paul Torgersen. It’s Tuesday July 26th, 2022 and from Denver, this is a look at the information security news from overnight.

From PortSwigger.net:
A critical vulnerability within a Grails application runtime could allow an attacker to gain remote code execution. The attack exploits a section of the Grails data-binding logic, and has been confirmed on Grails framework versions 3.3.10 and higher, including Grails framework 4 and 5, that are running on Java 8. It has been observed in both the embedded Tomcat runtime and applications deployed as a Web Archive to a Tomcat instance. The company urges all users, even those using unaffected versions, to update as soon as possible.

From TheHackerNews.com:
Threat actors are exploiting a previously unknown security flaw in the open source PrestaShop e-commerce platform to inject malicious skimmer code. PrestaShop is the leading open-source e-commerce solution in Europe and Latin America, used by nearly 300,000 online merchants worldwide. The company said they found a zero-day flaw in its service that has been addressed in version 1.7.8.7, although they are not sure that was the only flaw vulnerable to the attack.

From BleepingComputer.com:
A new spear phishing campaign named Ducktail is targeting professionals on LinkedIn to take over Facebook business accounts. The threat actors are specifically targeting people who have admin privileges on their employer’s social media accounts. Fingers point to a Vietnamese threat actor that has been active since at least 2021 and maybe back as far as 2018.

From Infosecurity-Magazine.com:
Indian insurance company Policybazaar has advised that it suffered a data breach, confirming an unauthorized access to their systems on July 19. The company has found and fixed the exploited vulnerability and claims that no significant customer data was exposed.

And last, from TheHackerNews.com:
FileWave's mobile device management system has been found vulnerable to two critical security flaws that could be leveraged to carry out remote attacks and seize control of a fleet of devices connected to it. The two flaws relate to an authentication bypass, and the use of a hard-coded cryptographic key. There are more than 1,100 internet-facing FileWave servers that are vulnerable to the attack. Get your patch on kids.

That’s all for me today. Have a great rest of your day. Like and subscribe, and until tomorrow, be safe out there.
...more
View all episodesView all episodes
Download on the App Store

Infosec Overnights - Daily Security NewsBy Paul Torgersen