πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-46363 β€Ό

An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted CSV/XLS file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46366 β€Ό

An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23633 β€Ό

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23634 β€Ό

Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAttributes` implementation to work correctly. The combination of these two behaviors (Puma not closing the body + Rails' Executor implementation) causes information leakage. This problem is fixed in Puma versions 5.6.2 and 4.3.11. This problem is fixed in Rails versions 7.02.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2. Upgrading to a patched Rails _or_ Puma version fixes the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Sophos to launch new data centre in Mumbai πŸ“’

The cyber security company will help organisations to comply with strict data sovereignty laws and regulations

πŸ“– Read

via "ITPro".
πŸ“’ Google Cloud adds cryptomining protection following widespread exploitation πŸ“’

In nearly all cases of compromised Google Cloud instances, cryptomining malware was installed within 22 seconds

πŸ“– Read

via "ITPro".
πŸ“’ Linux-based multi-cloud environments facing increased ransomware attacks πŸ“’

VMware researchers claim not enough effort is being spent on developing countermeasures for attacks on the cloud's most popular operating system

πŸ“– Read

via "ITPro".
πŸ“’ Washington State Department of Licensing hit by suspected data breach πŸ“’

The DOL temporarily disabled its POLARIS system to investigate a possible breach

πŸ“– Read

via "ITPro".
πŸ“’ Apple bug allowed iPhones to inadvertently record Siri interactions πŸ“’

The flaw stored Siri recordings even if a user had opted out

πŸ“– Read

via "ITPro".
πŸ“’ Online Safety Bill will require porn sites to verify age of UK users πŸ“’

However, internet users are concerned the proposal will threaten online privacy and open new opportunities for blackmail

πŸ“– Read

via "ITPro".
πŸ“’ Building IT antibodies to fight future shocks πŸ“’

As enterprises look towards their post-COVID futures, they must ensure their IT systems are robust, secure, and resilient

πŸ“– Read

via "ITPro".
πŸ“’ Google claims default 2FA reduced account breaches by 50% πŸ“’

The auto-enabled security mechanism was first introduced late last year

πŸ“– Read

via "ITPro".
πŸ“’ US seizes record $3.6 billion in Bitcoin from Bitfinex hack πŸ“’

The FBI has also arrested a married couple for allegedly conspiring to launder the stolen cryptocurrency

πŸ“– Read

via "ITPro".
πŸ“’ US indicts Indian call center scammers πŸ“’

Six call centers were responsible for millions of IRS and loan fraud scams, says DoJ

πŸ“– Read

via "ITPro".
πŸ“’ Foreign Office hit by β€œserious cyber security incident” πŸ“’

The department sought urgent assistance from its security contractor in light of the "emergency"

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft's Patch Tuesday fixes 70 vulnerabilities after a troublesome January update πŸ“’

Microsoft will be hoping for a bug-free round of patches after admins complained of January's updates breaking more components than they fixed

πŸ“– Read

via "ITPro".
πŸ“’ Swissport ransomware attack leads to flight delays πŸ“’

The attack is now 'under control' but raises questions around critical European businesses being targeted in recent weeks

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft disables VBA macros in Office by default following years of complaints πŸ“’

The move has been widely welcomed by the security industry, though concerns remain over the ease of implementation

πŸ“– Read

via "ITPro".
πŸ“’ DHS establishes the nation’s first Cyber Safety Review Board πŸ“’

The public-private initiative unites federal government and industry leaders to boost cyber security in the US

πŸ“– Read

via "ITPro".
πŸ“’ The top 12 password-cracking techniques used by hackers πŸ“’

Some of the most common, and most effective methods for stealing passwords

πŸ“– Read

via "ITPro".
πŸ“’ IRS backtracks on facial recognition plans following backlash πŸ“’

The turnabout was prompted by privacy concerns raised by taxpayers, lawmakers, and advocacy groups

πŸ“– Read

via "ITPro".