πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-22895 β€Ό

Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-helpers-conversion.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22929 β€Ό

MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22930 β€Ό

A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22928 β€Ό

MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Safari bug lets websites track browsing activity and unique identifiers πŸ“’

The flaw, found in Apple's WebKit browser engine, affects Safari 15 on macOS and all browsers on iOS and iPadOS 15

πŸ“– Read

via "ITPro".
πŸ“’ NSW ditches e-voting system after glitch left citizens unable to vote πŸ“’

The electoral commissioner is also seeking the validity of the results in three councillor elections

πŸ“– Read

via "ITPro".
πŸ“’ Aldi launches its first checkout-free store in London πŸ“’

The store uses facial age estimation technology provided by Yoti to verify the purchase of age-restricted products

πŸ“– Read

via "ITPro".
πŸ“’ European data regulators issued €1.1 billion in GDPR fines in 2021 πŸ“’

The UK placed sixth on the GDPR fine table with its Β£20 million fine levied against British Airways

πŸ“– Read

via "ITPro".
πŸ“’ IOC defends China Olympics app after 'devastating flaw' revealed πŸ“’

The app may even be breaking Google and Apple’s app store policies when it comes to privacy, according to Citizen Lab

πŸ“– Read

via "ITPro".
πŸ“’ NCA plots education drive to crack down on children exploring cyber crime πŸ“’

With children as young as nine being referred to the NCA for launching DDoS attacks, the new campaign aims to educate children in the consequences of cyber crime

πŸ“– Read

via "ITPro".
πŸ“’ A month in the life of a social engineer - part three πŸ“’

With the master plan now well underway, we learn how the hacker exploits their target's β€˜unpatchable’ human flaws to gain access to corporate systems

πŸ“– Read

via "ITPro".
πŸ“’ Skills 'deficit' forces Student Loans Company to spend heavily on temp staff πŸ“’

The organisation has spent Β£2.6 million on agency staff as it struggles to retain technical employees

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft warns full scope of Ukraine cyber attacks β€˜not fully realised’ πŸ“’

The company's investigation into the attacks targeting Ukraine revealed atypical characteristics of the "destructive" campaign that disguises itself as ransomware

πŸ“– Read

via "ITPro".
πŸ“’ The UK's IoT proposals are riddled with β€˜astonishing’ gaps πŸ“’

The Product Security and Telecommunications Infrastructure (PTSI) Bill aims to address the connected devices security nightmare, but experts agree it doesn’t go far enough

πŸ“– Read

via "ITPro".
πŸ“’ Windows Server admins agree to forgo broken patches πŸ“’

Many administrators have agreed to wait until February's round of patches to avoid operational disruption caused by broken fixes

πŸ“– Read

via "ITPro".
πŸ“’ Russia's "politically motivated" REvil raid could be used as leverage, experts warn πŸ“’

The cyber security industry says the FSB's arrests are β€œunlikely” to signal a change in Russia’s policy

πŸ“– Read

via "ITPro".
πŸ“’ FireEye and McAfee Enterprise relaunch as Trellix πŸ“’

The new pure-play cyber security firm’s platform combines automation, machine learning, and threat intelligence

πŸ“– Read

via "ITPro".
πŸ“’ White House issues memorandum to bolster national security systems πŸ“’

Agencies must now implement multi-factor authentication within 180 days, along with encryption for data at rest and in transit

πŸ“– Read

via "ITPro".
πŸ“’ Red Cross "appalled" by data breach targeting 515,000 vulnerable people πŸ“’

The charitable organisation has begged cyber attackers not to leak the data online in emotional plea

πŸ“– Read

via "ITPro".
πŸ“’ DHL overtakes Microsoft as the most imitated brand in phishing attacks πŸ“’

Check Point Research reveals that the logistics giant accounted for almost a quarter of global phishing attacks in 2021

πŸ“– Read

via "ITPro".
πŸ“’ UK and Australia partner on cyber security investment πŸ“’

The countries are set to invest in infrastructure for Indo-Pacific states as well, in the areas of energy, investment, and technology

πŸ“– Read

via "ITPro".