πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-21900 β€Ό

Windows Hyper-V Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2022-21905.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21929 β€Ό

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21930, CVE-2022-21931.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21963 β€Ό

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21892, CVE-2022-21928, CVE-2022-21958, CVE-2022-21959, CVE-2022-21960, CVE-2022-21961, CVE-2022-21962.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21887 β€Ό

Win32k Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21882.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21875 β€Ό

Windows Storage Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21964 β€Ό

Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21911 β€Ό

.NET Framework Denial of Service Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21930 β€Ό

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21929, CVE-2022-21931.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21880 β€Ό

Windows GDI+ Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-21915.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21891 β€Ό

Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21896 β€Ό

Windows DWM Core Library Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21852, CVE-2022-21902.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21834 β€Ό

Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21893 β€Ό

Remote Desktop Protocol Remote Code Execution Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Kiteworks Acquires Email Encryption Leader totemo πŸ•΄

Further closes intelligence gap inhibiting companies from tracking and controlling private content communications.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Kicks Off 2022 With 96 Security Patches πŸ•΄

Nine of the Microsoft patches released today are classified as critical, 89 are Important, and six are publicly known.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Let's Play! Raising the Stakes for Threat Modeling With Card Games πŸ•΄

On a recent Friday night, three security experts got together to play custom games that explore attack risks in an engaging way.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-0087 β€Ό

keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Who is the Network Access Broker β€˜Wazawaka?’ β™ŸοΈ

In a great many ransomware attacks, the criminals who pillage the victim's network are not the same crooks who gained the initial access to the victim organization. More commonly, the infected PC or stolen VPN credentials the gang used to break in were purchased from a cybercriminal middleman known as an initial access broker. This post examines some of the clues left behind by Wazawaka, the handle chosen by a major access broker in the Russian-speaking cybercrime scene.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2022-0159 β€Ό

orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-0179 β€Ό

snipe-it is vulnerable to Improper Access Control

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ—“οΈ Moodle e-learning platform patches session hijack bug that led to pre-auth RCE πŸ—“οΈ

Researchers disclose second critical flaw in authentication plugin

πŸ“– Read

via "The Daily Swig".