๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด CrowdStrike Incorporates Intel CPU Telemetry into Falcon Sensor ๐Ÿ•ด

The Falcon sensor uses Intel PT telemetry to identify suspicious operations associated with hard-to-detect exploit techniques.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2021-43946 โ€ผ

Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.21.0.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-22567 โ€ผ

Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-41043 โ€ผ

Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-31589 โ€ผ

BeyondTrust Secure Remote Access Base Software through 6.0.1 allows an attacker to achieve full admin access to the appliance, by tricking the administrator into creating a new admin account through an XSS/CSRF attack involving a crafted request to the /appliance/users?action=edit endpoint. This cross-site-scripting (XSS) vulnerability occurs when it does not properly sanitize an unauthenticated crafted web request to the server

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-15933 โ€ผ

A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially sensitive software-version information via client-side resources inspection.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ—“๏ธ Indian academic bookseller Oswaal Books fixes alleged RCE and other serious vulnerabilities with Shopify relaunch ๐Ÿ—“๏ธ

Researcher claims he found RCE, authentication bypass, CSRF flaws

๐Ÿ“– Read

via "The Daily Swig".
โŒ โ€˜Malsmokeโ€™ Exploits Microsoftโ€™s E-Signature Verification โŒ

The info-stealing campaign using ZLoader malware โ€“ previously used to deliver Ryuk and Conti ransomware โ€“ already has claimed more than 2,000 victims across 111 countries.

๐Ÿ“– Read

via "Threat Post".
๐Ÿ—“๏ธ Web skimming attacks on hundreds of real estate websites deployed via cloud video hosting service ๐Ÿ—“๏ธ

Attackers leverage software supply chain to compromise high-traffic sites

๐Ÿ“– Read

via "The Daily Swig".
๐Ÿ•ด Putting Ransomware Gangs Out of Business With AI ๐Ÿ•ด

Organizations need to take matters into their own hands with a new approach.

๐Ÿ“– Read

via "Dark Reading".
โš  Apple Home software bug could lock you out of your iPhone โš 

The finder of this bug insists it "poses a serious risk". We're not so sure, but we recommend you take steps to avoid it anyway.

๐Ÿ“– Read

via "Naked Security".
โš  FTC threatens โ€œlegal actionโ€ over unpatched Log4j and other vulns โš 

Remember the Equifax breach? Remember the $700m penalty? In case you'd forgotten, here's the FTC to refresh your memory!

๐Ÿ“– Read

via "Naked Security".
๐Ÿ—“๏ธ Prosecutors file additional charges against former Uber security chief over 2016 data breach โ€˜cover upโ€™ ๐Ÿ—“๏ธ

Alleged misuse of bug bounty and failure to disclose breach leads to criminal charges

๐Ÿ“– Read

via "The Daily Swig".
โ€ผ CVE-2022-22110 โ€ผ

In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force usersรขโ‚ฌโ„ข passwords with minimal to no computational effort.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-22108 โ€ผ

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-22111 โ€ผ

In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administratorรขโ‚ฌโ„ขs. This allows the attacker to gain access to the highest privileged user in the application.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-22109 โ€ผ

In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store malicious scripts in the title field of new tasks. These scripts are executed in a victimรขโ‚ฌโ„ขs browser when they open the รขโ‚ฌล“/tasksรขโ‚ฌ๏ฟฝ page to view all the tasks.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-22107 โ€ผ

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not authorized to view the calendar at all.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Why We Need To Reframe the False-Positive Problem ๐Ÿ•ด

Efforts to tune or build behavior- or signature-based threat identification requires time and effort most organizations don't have.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿฆฟ Behind the scenes: A day in the life of a cybersecurity curriculum director ๐Ÿฆฟ

The Kennedy Space Center kick-started Andee Harston's career in cybersecurity. Here's how she worked her way up to overseeing the cybersecurity curriculum for Infosec.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿฆฟ MalSmoke attack: Zloader malware exploits Microsoft's signature verification to steal sensitive data ๐Ÿฆฟ

Already impacting more than 2,000 victims, the malware is able to modify a DLL file digitally signed by Microsoft, says Check Point Research.

๐Ÿ“– Read

via "Tech Republic".