πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 WAN report: Complexity continue to grow as more organizations close legacy data centers 🦿

The sixth annual report from Aryaka found that IT teams are planning to invest more in 2022 but expect more transparency and control.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Red Cross suffers cyber-attack – data of 515,000 β€˜highly vulnerable’ people exposed πŸ—“οΈ

The β€˜sophisticated’ attack was detected last week

πŸ“– Read

via "The Daily Swig".
❌ SEC Filing Reveals Fortune 500 Firm Targeted in Ransomware Attack ❌

The Fortune 500 integrated services company confirmed a β€˜systems intrusion’ that occurred in late December and is still under investigation in an SEC filing.

πŸ“– Read

via "Threat Post".
πŸ•΄ 4 Ways to Develop Your Team's Cyber Skills πŸ•΄

Organizations need to invest in professional development β€” and then actually make time for it.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ White House orders federal agencies to raise cybersecurity bar for national security systems πŸ—“οΈ

New guidance will bring standards into line with federal civilian networks

πŸ“– Read

via "The Daily Swig".
❌ Red Cross Begs Attackers Not to Leak 515K People’s Stolen Data ❌

The Red Cross was forced to shut down IT systems behind its Restoring Family Links system, which reunites families separated by war, disaster or migration.

πŸ“– Read

via "Threat Post".
❌ Pervasive Apple Safari Bug Exposes Web-Browsing Data, Google IDs ❌

The information-disclosure issue, affecting Macs, iPhones and iPads, allows a snooping website to find out information about other tabs a user might have open.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-0285 β€Ό

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32039 β€Ό

Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44738 β€Ό

Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis [Podcast + Transcript] ⚠

Latest epsiode - listen now!

πŸ“– Read

via "Naked Security".
πŸ•΄ Enterprises Are Sailing Into a Perfect Storm of Cloud Risk πŸ•΄

Policy as code and other techniques can help enterprises steer clear of the dangers that have befallen otherwise sophisticated cloud customers.

πŸ“– Read

via "Dark Reading".
🦿 Secure your passwords and access them anywhere with LastPass 🦿

LastPass's Premium Plan keeps your digital life secure and at your fingertips with management for an unlimited number of passwords and seamless access across all of your devices.

πŸ“– Read

via "Tech Republic".
πŸ›  AIDE 0.17.4 πŸ› 

AIDE (Advanced Intrusion Detection Environment) is a free replacement for Tripwire(tm). It generates a database that can be used to check the integrity of files on server. It uses regular expressions for determining which files get added to the database. You can use several message digest algorithms to ensure that the files have not been tampered with.

πŸ“– Read

via "Packet Storm Security".
πŸ›  GRAudit Grep Auditing Tool 3.3 πŸ› 

Graudit is a simple script and signature sets that allows you to find potential security flaws in source code using the GNU utility, grep. It's comparable to other static analysis applications like RATS, SWAAT, and flaw-finder while keeping the technical requirements to a minimum and being very flexible.

πŸ“– Read

via "Packet Storm Security".
🦿 Microsoft RDP vulnerability makes it a breeze for attackers to become men-in-the-middle 🦿

The Microsoft RDP vulnerability is a serious problem, but with a few caveats: It's been patched, and experts say it may be less likely to happen than it seems at first glance.

πŸ“– Read

via "Tech Republic".
❌ Microsoft Sees Log4j Attacks Exploiting SolarWinds Serv-U Bug ❌

SolarWinds has fixed a Serv-U bug that threat actors were exploiting to unleash Log4j attacks on networks’ internal devices.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-44829 β€Ό

Cross Site Scripting (XSS) vulnerability exists in index.html in AFI WebACMS through 2.1.0 via the the ID parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44735 β€Ό

Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45417 β€Ό

AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44091 β€Ό

A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.

πŸ“– Read

via "National Vulnerability Database".