πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-0277 β€Ό

Improper Access Control in Packagist microweber/microweber prior to 1.2.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0278 β€Ό

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Eleven prolific BEC scam suspects arrested in Nigeria πŸ—“οΈ

SilverTerrier brought to heel

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0281 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34600 β€Ό

Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for authorization of users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22820 β€Ό

Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45230 β€Ό

In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3866 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip prior to main.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0282 β€Ό

Code Injection in Packagist microweber/microweber prior to 1.2.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22733 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cisco's Kenna Security Research Shows the Relative Likelihood of an Organization Being Exploited πŸ•΄

A record-breaking 20,130 vulnerabilities were reported in 2021. However, only 4% pose a high risk to organizations.

πŸ“– Read

via "Dark Reading".
🦿 WAN report: Complexity continue to grow as more organizations close legacy data centers 🦿

The sixth annual report from Aryaka found that IT teams are planning to invest more in 2022 but expect more transparency and control.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Red Cross suffers cyber-attack – data of 515,000 β€˜highly vulnerable’ people exposed πŸ—“οΈ

The β€˜sophisticated’ attack was detected last week

πŸ“– Read

via "The Daily Swig".
❌ SEC Filing Reveals Fortune 500 Firm Targeted in Ransomware Attack ❌

The Fortune 500 integrated services company confirmed a β€˜systems intrusion’ that occurred in late December and is still under investigation in an SEC filing.

πŸ“– Read

via "Threat Post".
πŸ•΄ 4 Ways to Develop Your Team's Cyber Skills πŸ•΄

Organizations need to invest in professional development β€” and then actually make time for it.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ White House orders federal agencies to raise cybersecurity bar for national security systems πŸ—“οΈ

New guidance will bring standards into line with federal civilian networks

πŸ“– Read

via "The Daily Swig".
❌ Red Cross Begs Attackers Not to Leak 515K People’s Stolen Data ❌

The Red Cross was forced to shut down IT systems behind its Restoring Family Links system, which reunites families separated by war, disaster or migration.

πŸ“– Read

via "Threat Post".
❌ Pervasive Apple Safari Bug Exposes Web-Browsing Data, Google IDs ❌

The information-disclosure issue, affecting Macs, iPhones and iPads, allows a snooping website to find out information about other tabs a user might have open.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-0285 β€Ό

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32039 β€Ό

Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44738 β€Ό

Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.

πŸ“– Read

via "National Vulnerability Database".