πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ More Security Flaws Found in Apple's OS Technologies πŸ•΄

Apple's updates this week included fixes for two zero-day flaws, several code execution bugs, and vulnerabilities that allowed attackers to bypass its core security protections.

πŸ“– Read

via "Dark Reading".
⚠ Apple fixes Safari data leak (and patches a zero-day!) – update now ⚠

That infamous "supercookie" bug in Safari has now been fixed. Oh, and there was a zero-day kernel hole as well.

πŸ“– Read

via "Naked Security".
⚠ S3 Ep67: Tax scams, carder busts and crypto capers [Podcast + Transcript] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
❌ Conti, DeadBolt Target Delta, QNAP ❌

QNAP had to push out an unexpected (and not entirely welcome) NAS device update, and Delta Electronics' network has been crippled.

πŸ“– Read

via "Threat Post".
❌ Shlayer and Bundlore MacOS Malware Strains – How Uptycs EDR Detection Can Help ❌

MacOS malware Shlayer and Bundlore may have variations, but the behavior of their attacks have not changed – attacking older macOS versions and poorly-protected websites.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-42791 β€Ό

An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD enrolled users does not enforce proper access control. A user can trigger push notifications for any other user. The text contained in the push notification can also be modified. If a user who receives the notification accepts it, then the user who triggered the notification can obtain the accepting user's login certificate.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ US government’s β€˜zero trust’ roadmap calls time on perimeter-based paradigm πŸ—“οΈ

Federal agencies have a little over two years to fundamentally remodel cyber defenses

πŸ“– Read

via "The Daily Swig".
⚠ Happy Data Privacy Day – and we really do mean β€œhappy” :-) ⚠

We give you some simple digital lifesytle tips that cost nothing.

πŸ“– Read

via "Naked Security".
❌ Zerodium Spikes Payout for Zero-Click Outlook Zero-Days ❌

The sweetened deal came on the same day that Trustwave SpiderLabs published a new way to bypass Outlook security to deliver malicious links to victims.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-23098 β€Ό

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44249 β€Ό

Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23863 β€Ό

Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23097 β€Ό

An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45435 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25905 β€Ό

An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23096 β€Ό

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read.

πŸ“– Read

via "National Vulnerability Database".
🦿 Kaspersky stopped more than 30,000 attempts to use the Log4Shell exploit in January 🦿

The critical remote code execution vulnerability in Apache's Log4j utility continues to be a popular tactic for cybercriminals. Consider this yet another plea to patch your systems.

πŸ“– Read

via "Tech Republic".
πŸ•΄ The Looming CISO Mental Health Crisis β€” and What to Do About It, Part 1 πŸ•΄

The next big threat to corporate security may not be a new strain of malware or innovative attacker tactics, techniques, and processes. It may be our own mental health.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-34073 β€Ό

A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22294 β€Ό

A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foreground and add a background administrator account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45898 β€Ό

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.

πŸ“– Read

via "National Vulnerability Database".