[FD] APPLE-SA-2022-01-26-6 watchOS 8.4

2022-01-28 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2022-01-26-6 watchOS 8.4 watchOS 8.4 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213059. ColorSync Available for: Apple Watch Series 3 and later Impact:

[FD] APPLE-SA-2022-01-26-7 Safari 15.3

2022-01-28 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2022-01-26-7 Safari 15.3 Safari 15.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213058. WebKit Available for: macOS Big Sur and macOS Catalina Impact:

[FD] APPLE-SA-2022-01-26-5 tvOS 15.3

2022-01-28 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2022-01-26-5 tvOS 15.3 tvOS 15.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213057. ColorSync Available for: Apple TV 4K and Apple TV HD Impact: Processing a

[FD] APPLE-SA-2022-01-26-3 macOS Big Sur 11.6.3

2022-01-28 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2022-01-26-3 macOS Big Sur 11.6.3 macOS Big Sur 11.6.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213055. Audio Available for: macOS Big Sur Impact: Parsing a

[FD] APPLE-SA-2022-01-26-2 macOS Monterey 12.2

2022-01-28 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2022-01-26-2 macOS Monterey 12.2 macOS Monterey 12.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213054. AMD Kernel Available for: macOS Monterey Impact: A

[FD] Backdoor.Win32.WinShell.50 / Weak Hardcoded Password

2022-01-28 Thread malvuln
Discovery / credits: Malvuln - malvuln.com (c) 2022 Original source: https://malvuln.com/advisory/1fd45364073a81ddd707d74ba5d4c121.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: Backdoor.Win32.WinShell.50 Vulnerability: Weak Hardcoded Password Description: The malware listens

[FD] APPLE-SA-2022-01-26-4 Security Update 2022-001 Catalina

2022-01-28 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2022-01-26-4 Security Update 2022-001 Catalina Security Update 2022-001 Catalina addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213056. Kernel Available for: macOS

[FD] APPLE-SA-2022-01-26-1 iOS 15.3 and iPadOS 15.3

2022-01-28 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2022-01-26-1 iOS 15.3 and iPadOS 15.3 iOS 15.3 and iPadOS 15.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213053. ColorSync Available for: iPhone 6s and later,

[FD] CarolinaCon Online 2

2022-01-28 Thread Carolina Con
We hope this email finds you well. CarolinaCon Online 2 will be hosted April 29th to May 1st 2022. The conference will be virtual and submitted talks will be live streamed. Last year we used discord for conference communication and for this year we will do the same but will provide a bridged

[FD] KL-001-2022-002: Moxa TN-5900 Post Authentication Command Injection Vulnerability

2022-01-28 Thread KoreLogic Disclosures via Fulldisclosure
KL-001-2022-002: Moxa TN-5900 Post Authentication Command Injection Vulnerability Title: Moxa TN-5900 Post Authentication Command Injection Vulnerability Advisory ID: KL-001-2022-002 Publication Date: 2022.01.28 Publication URL: https://korelogic.com/Resources/Advisories/KL-001-2022-002.txt 1.

[FD] KL-001-2022-001: Moxa TN-5900 Firmware Upgrade Checksum Validation Vulnerability

2022-01-28 Thread KoreLogic Disclosures via Fulldisclosure
KL-001-2022-001: Moxa TN-5900 Firmware Upgrade Checksum Validation Vulnerability Title: Moxa TN-5900 Firmware Upgrade Checksum Validation Vulnerability Advisory ID: KL-001-2022-001 Publication Date: 2022.01.28 Publication URL: https://korelogic.com/Resources/Advisories/KL-001-2022-001.txt 1.