πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Vectra Acquires Siriux Security Technologies to Extend Leadership in Identity and SaaS Threat Management πŸ•΄

The acquisition positions Vectra to help customers securely configure and detect active threats in cloud identity and SaaS applications, including Microsoft Azure AD and Microsoft 365.

πŸ“– Read

via "Dark Reading".
❌ FBI: Use a Burner Phone at the Olympics ❌

The warning follows a Citizen Lab report that found the official, mandatory app has an encryption flaw that "can be trivially sidestepped." Besides burners, here are more tips on staying cyber-safe at the Games.

πŸ“– Read

via "Threat Post".
πŸ•΄ Nucleus Security Forms Strategic Partnership with Mandiant πŸ•΄

Intent is to enhance vulnerability management programs with operationalized threat intelligence.

πŸ“– Read

via "Dark Reading".
πŸ•΄ ThycoticCentrify Renamed Delinea πŸ•΄

Privileged access management vendor rebrands.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Secure Web Browsers Tackle Ransomware, Insider Threat in Enterprises πŸ•΄

Enterprise security teams can use secure web browsers to apply controls and governance to cloud applications and customer data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42638 β€Ό

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ QNAP ransomware victims dealt double blow as firmware update hampers decryption πŸ“’

Emisoft releases decryptor for victims while QNAP explains why and how it controversially auto-updated user’s products

πŸ“– Read

via "ITPro".
πŸ“’ MoD reported seven data incidents to the ICO between 2020 and 2021 πŸ“’

More than 4,000 people were affected according to the department's Annual Report and Accounts

πŸ“– Read

via "ITPro".
πŸ“’ Log4j vulnerability continues to stress CISOs πŸ“’

Avast's latest threat report also reveals the resurrection of the infamous Emotet botnet

πŸ“– Read

via "ITPro".
πŸ“’ The best defence against ransomware πŸ“’

How ransomware is evolving and how to defend against it

πŸ“– Read

via "ITPro".
πŸ“’ QNAP users angry after NAS drives are updated to combat DeadBolt ransomware πŸ“’

Concerns mount over the powers the NAS manufacturer has over users' products as users report non-consensual forced security updates

πŸ“– Read

via "ITPro".
πŸ“’ FBI urges Olympic athletes to leave personal devices at home due to cyber risk πŸ“’

The organisation has warned that threat actors could use a broad range of cyber activities, including DDoS or ransomware attacks, to disrupt the event

πŸ“– Read

via "ITPro".
πŸ“’ Google adds Python support to privacy-preserving data analysis tool πŸ“’

The addition of Python opens up the open-source differential privacy library to nearly half of all developers worldwide

πŸ“– Read

via "ITPro".
πŸ“’ IT Pro News in Review: Nvidia walks away from Arm, Belarusian train hack, and IBM to sell Watson Health πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-24300 β€Ό

Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24301 β€Ό

In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ British Council data breach leaks 10,000 student records πŸ—“οΈ

Researchers say 144,000 files were exposed

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0366 β€Ό

An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41016 β€Ό

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands including special characters

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39066 β€Ό

IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43062 β€Ό

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.

πŸ“– Read

via "National Vulnerability Database".