πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Microsoft Kicks Off 2022 With 96 Security Patches πŸ•΄

Nine of the Microsoft patches released today are classified as critical, 89 are Important, and six are publicly known.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Let's Play! Raising the Stakes for Threat Modeling With Card Games πŸ•΄

On a recent Friday night, three security experts got together to play custom games that explore attack risks in an engaging way.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-0087 β€Ό

keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Who is the Network Access Broker β€˜Wazawaka?’ β™ŸοΈ

In a great many ransomware attacks, the criminals who pillage the victim's network are not the same crooks who gained the initial access to the victim organization. More commonly, the infected PC or stolen VPN credentials the gang used to break in were purchased from a cybercriminal middleman known as an initial access broker. This post examines some of the clues left behind by Wazawaka, the handle chosen by a major access broker in the Russian-speaking cybercrime scene.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2022-0159 β€Ό

orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-0179 β€Ό

snipe-it is vulnerable to Improper Access Control

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ—“οΈ Moodle e-learning platform patches session hijack bug that led to pre-auth RCE πŸ—“οΈ

Researchers disclose second critical flaw in authentication plugin

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-3852 β€Ό

growi is vulnerable to Authorization Bypass Through User-Controlled Key

πŸ“– Read

via "National Vulnerability Database".
❌ Phishers Rip Off High-Profile EA Gamers ❌

Electronic Arts blamed β€œhuman error” after attackers compromised customer support and took over and drained some of the top FIFA Ultimate Team player accounts.

πŸ“– Read

via "Threat Post".
🦿 Cisco Talos discovers a new malware campaign using the public cloud to hide its tracks 🦿

The campaign was first detected in October and is using services like AWS and Azure to hide its tracks and evade detection.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Firefox fixes fullscreen notification bypass bug that could have led to convincing phishing campaigns πŸ—“οΈ

Flurry of issues patched in web browser’s latest advisory

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-4080 β€Ό

crater is vulnerable to Unrestricted Upload of File with Dangerous Type

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44648 β€Ό

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44649 β€Ό

Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44650 β€Ό

Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.

πŸ“– Read

via "National Vulnerability Database".
⚠ Home routers with NetUSB support could have critical kernel hole ⚠

Got a router that supports USB access across the network? You might need a kernel update...

πŸ“– Read

via "Naked Security".
⚠ JavaScript developer destroys own projects in supply chain β€œlesson” ⚠

Two popular open source JavaScript packages recently got "hacked" in a symbolic gesture by the original project creator.

πŸ“– Read

via "Naked Security".
πŸ•΄ Patch Management Today: A Risk-Based Strategy to Defeat Cybercriminals πŸ•΄

By combining risk-based vulnerability prioritization and automated patch intelligence, organizations can apply patches based on threat level. Part 2 of 3.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Patch Tuesday: Web security issues in the spotlight in Microsoft’s bumper January update πŸ—“οΈ

β€˜Wormable’ flaw in HTTP Protocol Stack causes concern

πŸ“– Read

via "The Daily Swig".
πŸ›  Proxmark3 4.14831 πŸ› 

This is a custom firmware written for the Proxmark3 device. It extends the currently available firmware. This release is nicknamed Frostbit.

πŸ“– Read

via "Packet Storm Security".
πŸ—“οΈ Cybersecurity conferences 2022: A rundown of online, in person, and β€˜hybrid’ events πŸ—“οΈ

With many events choosing to retain virtual elements forced on them by the pandemic, there’s now an abundance of online content to choose from

πŸ“– Read

via "The Daily Swig".