πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2012-3340

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to XML external entity injection, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 78291.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-3338

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to bypass security restrictions, caused by improper restrictions on the create new user account functionality. An attacker could exploit this vulnerability to create unprivileged user accounts. IBM X-Force ID: 78286.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-3337

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to download arbitrary files on the system. IBM X-Force ID: 78284.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-3336

IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to multiple scripts, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 78282.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ New APT Pioneer Kitten Linked to Iranian Government πŸ•΄

The group's targets have primarily been North American and Israeli entities, with a focus on technology, government, defense, and healthcare.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Apple Signs Shlayer, Legitimizes Malware πŸ•΄

Shlayer, a common macOS Trojan, received Apple's notary certification and place in the App Store -- twice.

πŸ“– Read

via "Dark Reading: ".
❌ Magento Sites Vulnerable to RCE Stemming From Magmi Plugin Flaws ❌

Two flaws - one of them yet to be fixed - are afflicting a third-party plugin used by Magento e-commerce websites.

πŸ“– Read

via "Threatpost".
πŸ•΄ Anti-Phishing Startup Pixm Aims to Hook Browser-Based Threats πŸ•΄

Pixm visually analyzes phishing websites from a human perspective to detect malicious pages people might otherwise miss.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New Threat Activity by Lazarus Group Spells Trouble For Orgs πŸ•΄

The North Korea-backed group has launched several campaigns to raise revenue for cash-strapped nation's missile program, security experts say.

πŸ“– Read

via "Dark Reading: ".
❌ Chinese APT Debuts Sepulcher Malware in Spear-Phishing Attacks ❌

The RAT has been distributed in various campaigns over the past six months, targeting both European officials and Tibetan dissidents.

πŸ“– Read

via "Threatpost".
❌ Cisco Warns of Active Exploitation of Flaw in Carrier-Grade Routers ❌

Multiple flaws in system software that causes errors in packet handling could allow an attacker to consume memory and crash devices.

πŸ“– Read

via "Threatpost".
❌ Live Webinar: XDR and Beyond ❌

Next week, Senior Analyst Dave Gruber of ESG will join cybersecurity company Cynet for a webinar to help companies better understand the promise and realities of emerging XDR technologies

πŸ“– Read

via "Threatpost".
⚠ Phishing scam uses Sharepoint and One Note to go after passwords ⚠

Not all phishing links appear right in the email itself...

πŸ“– Read

via "Naked Security".
πŸ•΄ Hypothesis: Cyber Attackers Are After Your Scientific Research πŸ•΄

From COVID-19 treatment to academic studies, keeping research secure is more important than ever. The ResearchSOC at Indiana University intends to help.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why Kubernetes Clusters Are Intrinsically Insecure (& What to Do About Them) πŸ•΄

By following best practices and prioritizing critical issues, you can reduce the chances of a security breach and constrain the blast radius of an attempted attack. Here's how.

πŸ“– Read

via "Dark Reading: ".
πŸ” 33% of companies expose unsafe network services to the internet πŸ”

The findings of a new report validate the correlation between poor network hygiene and the prevalence of wider security issues in the digital supply chain.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How insider threats pose risks and challenges to any organization πŸ”

Insider threats can be difficult to combat and manage due to budgetary limits, lack of staff, and insufficient tools, says Bitglass.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ DHS Partners with Industry to Offer State, Local Gov'ts Cybersecurity Aid πŸ•΄

The US Department of Homeland Security teams up with Akamai and the Center for Internet Security to provide state and local governments with cybersecurity through DNS for free.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 5 Tips for Triaging Risk from Exposed Credentials πŸ•΄

Not all exposed usernames and passwords present a threat. Here's how to quickly identify the ones that do.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to enable end-to-end encryption for the Nextcloud app πŸ”

Learn how you can enable the new Nextcloud end-to-end encryption.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Replace your passwords with passphrases: Here's how to use them to remain secure πŸ”

Instead of trying to remember a long and complex password, try switching to passphrases. Learn why they're important and how they work.

πŸ“– Read

via "Security on TechRepublic".