πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24197 β€Ό

iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24221 β€Ό

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24218 β€Ό

An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46093 β€Ό

eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.

πŸ“– Read

via "National Vulnerability Database".
❌ Unpatched Security Bugs in Medical Wearables Allow Patient Tracking, Data Theft ❌

Rising critical unpatched vulnerabilities and a lack of encryption leave medical device data defenseless, researcher warn.

πŸ“– Read

via "Threat Post".
πŸ•΄ Digital Shadows Launches New Vulnerability Intelligence Module πŸ•΄

New capability simplifies challenge of prioritizing CVEs for faster triage and remediation.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Disclosure, Panic, Patch: Can We Do Better? πŸ•΄

Companies struggle to understand the extent to which they are affected by vulnerabilities in open source software, but security specialists and maintainers are striving to secure the ecosystem.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Forescout Acquires CyberMDX to Expand Healthcare Cybersecurity Focus πŸ•΄

Acquisition adds Internet of Medical Things (IoMT) expertise to Forescout’s IT, IoT, and OT coverage.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ping Identity Launches PingOne DaVinci πŸ•΄

No-code identity orchestration service enables organizations to design better user experiences with drag-and-drop simplicity.

πŸ“– Read

via "Dark Reading".
πŸ•΄ ShiftLeft CORE 'Velocity Update' Streamlines Triage, Automates Build Security Controls πŸ•΄

New features empower developers and AppSec teams to streamline the triage process and automate security controls.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Vectra Acquires Siriux Security Technologies to Extend Leadership in Identity and SaaS Threat Management πŸ•΄

The acquisition positions Vectra to help customers securely configure and detect active threats in cloud identity and SaaS applications, including Microsoft Azure AD and Microsoft 365.

πŸ“– Read

via "Dark Reading".
❌ FBI: Use a Burner Phone at the Olympics ❌

The warning follows a Citizen Lab report that found the official, mandatory app has an encryption flaw that "can be trivially sidestepped." Besides burners, here are more tips on staying cyber-safe at the Games.

πŸ“– Read

via "Threat Post".
πŸ•΄ Nucleus Security Forms Strategic Partnership with Mandiant πŸ•΄

Intent is to enhance vulnerability management programs with operationalized threat intelligence.

πŸ“– Read

via "Dark Reading".
πŸ•΄ ThycoticCentrify Renamed Delinea πŸ•΄

Privileged access management vendor rebrands.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Secure Web Browsers Tackle Ransomware, Insider Threat in Enterprises πŸ•΄

Enterprise security teams can use secure web browsers to apply controls and governance to cloud applications and customer data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42638 β€Ό

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ QNAP ransomware victims dealt double blow as firmware update hampers decryption πŸ“’

Emisoft releases decryptor for victims while QNAP explains why and how it controversially auto-updated user’s products

πŸ“– Read

via "ITPro".
πŸ“’ MoD reported seven data incidents to the ICO between 2020 and 2021 πŸ“’

More than 4,000 people were affected according to the department's Annual Report and Accounts

πŸ“– Read

via "ITPro".
πŸ“’ Log4j vulnerability continues to stress CISOs πŸ“’

Avast's latest threat report also reveals the resurrection of the infamous Emotet botnet

πŸ“– Read

via "ITPro".
πŸ“’ The best defence against ransomware πŸ“’

How ransomware is evolving and how to defend against it

πŸ“– Read

via "ITPro".
πŸ“’ QNAP users angry after NAS drives are updated to combat DeadBolt ransomware πŸ“’

Concerns mount over the powers the NAS manufacturer has over users' products as users report non-consensual forced security updates

πŸ“– Read

via "ITPro".