πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24307 β€Ό

Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft: Multifactor Adoption Remains Low πŸ•΄

New data shows a slow roll to strong authentication for most enterprise Windows systems.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Research From Quantum and ESG Reveals Top Challenges in Data Management πŸ•΄

Unstructured data management, storage complexity and cost remain barriers to adoption, resulting in valuable data being discarded or mismanaged.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Menlo Security Finds Cloud Migration and Remote Work Gives Rise to New Era of Malware, Highly Evasive Adaptive Threats (HEAT) πŸ•΄

Menlo identified 224% increase in HEAT attacks in the last six months fueling ransomware surge.

πŸ“– Read

via "Dark Reading".
πŸ•΄ DHS Launches Cyber Safety Review Board to Analyze Major Vulnerability Events πŸ•΄

The US Department of Homeland Security has named a 15-member review board to assess significant cybersecurity events and recommend improvements - starting with the Log4J vulnerability.

πŸ“– Read

via "Dark Reading".
❌ Low-Detection Phishing Kits Increasingly Bypass MFA ❌

A growing class of phishing kits – transparent reverse proxy kits – are being used to get past multi-factor authentication using MiTM tactics.

πŸ“– Read

via "Threat Post".
πŸ•΄ Several India-Based Call Centers Indicted by US DoJ πŸ•΄

"Scam robocall" operators face charges for defrauding US citizens.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Future of Cybersecurity: Our Predictions for 2022 πŸ•΄

New technologies and workplace trends are fueling a global explosion in cybercrime. Discover the threats to watch out for in 2022.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Tenable Launches Suite of New Features to Cloud-Native Application Security Platform πŸ•΄

Tenable.cs enhancements secure cloud resources, container images, and cloud assets

πŸ“– Read

via "Dark Reading".
πŸ•΄ Mandiant Bolsters SaaS Platform With Integration of New Attack Surface Management Module πŸ•΄

New automated offering helps organizations gain comprehensive visibility across IT environments, continuously monitor for vulnerabilities, operationalize threat intelligence and manage risk.

πŸ“– Read

via "Dark Reading".
❌ Kronos Still Dragging Itself Back From Ransomware Hell ❌

And customers including Tesla, PepsiCo and NYC transit workers are filing lawsuits over the β€œreal pain in the rear end” of manual inputting, inaccurate wages & more.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-45268 β€Ό

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Mac Malware-Dropping Adware Gets More Dangerous πŸ•΄

The authors of UpdateAgent have tweaked it yet again β€” for the fifth time in less than 18 months.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24153 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formAddMacfilterRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45989 β€Ό

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function guestWifiRuleRefresh. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qosGuestUpstream and qosGuestDownstream parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45987 β€Ό

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46230 β€Ό

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24172 β€Ό

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBindRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the addDhcpRules parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24148 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers to execute arbitrary commands via the dmzIp parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45995 β€Ό

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetStaticRoute. This vulnerability allows attackers to cause a Denial of Service (DoS) via the staticRouteNet, staticRouteMask, and staticRouteGateway parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24145 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formWifiBasicSet. This vulnerability allows attackers to cause a Denial of Service (DoS) via the security and security_5g parameters.

πŸ“– Read

via "National Vulnerability Database".