πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-42637 β€Ό

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42640 β€Ό

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42642 β€Ό

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Managing Detections is Not the Same as Stopping Breaches πŸ•΄

Enterprises interested in managed detection and response (MDR) services to monitor endpoints and workloads should make sure the providers have rock-solid expertise in detecting and responding to threats.

πŸ“– Read

via "Dark Reading".
❌ Supply-Chain Security Is Not a Problem…It’s a Predicament ❌

Despite what security vendors might say, there is no way to comprehensively solve our supply-chain security challenges, posits JupiterOne CISO Sounil Yu. We can only manage them.

πŸ“– Read

via "Threat Post".
πŸ” Engineering Data Protection by Design πŸ”

Appropriate safeguards, both technical and organizational, must be integrated into data processing operations from the very early steps.

πŸ“– Read

via "".
β€Ό CVE-2021-39021 β€Ό

IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration. IBM X-Force ID: 213856.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ WhiteSource Threat Report Reveals Massive Uptick In Cyberattacks Related To JavaScript npm πŸ•΄

More than 1,300 malicious npm packages have been discovered for use in supply chain attacks, cryptojacking, data stealing, and more.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Foresite Cybersecurity Acquires Cyber Lantern πŸ•΄

Support for more than 160 important compliance standards have been integrated into SaaS solution for small and midsize enterprises.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Why Security Pros Are Frustrated With Cloud Security πŸ•΄

As companies shift more operations to the cloud, a shortfall in security talent and too much security data wastes more than half of the time spent on security issues, a survey finds.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cato Networks Delivers Instant Visibility and Control of Cloud Application Data Risk πŸ•΄

CASB Cato converges a full CASB into its global SASE platform to defend enterprises against data breach and cloud-delivered threats.

πŸ“– Read

via "Dark Reading".
πŸ•΄ INKY Completes Email Security Offering With Launch of Outbound Mail Protection πŸ•΄

INKY Outbound Mail Protection manages a multistep approval workflow providing enforcement within the email system itself.

πŸ“– Read

via "Dark Reading".
❌ KP Snacks Left with Crumbs After Ransomware Attack ❌

The Conti gang strikes again, disrupting the nom-merchant's supply chain and threatening empty supermarket shelves lasting for weeks.

πŸ“– Read

via "Threat Post".
πŸ•΄ If My Organization Is Mostly in the Cloud, Do I Need a Firewall? πŸ•΄

A firewall is still a valuable part of the IT security stack, but businesses need to consider all their attack surfaces.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-0443 β€Ό

Use After Free in Conda vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0432 β€Ό

Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24121 β€Ό

SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43615 β€Ό

SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42060 β€Ό

SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42554 β€Ό

SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41838 β€Ό

An unsafe pointer vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler. An attacker can use this unsafe pointer "ptr" to read or write or manipulate data in the SMRAM. Exploitation of this vulnerability can lead to escalation of privileges reserved only for SMM using the SwSMI handler.

πŸ“– Read

via "National Vulnerability Database".