πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Google Chrome update fixes zero-day under active exploitation πŸ“’

Google releases a fresh wave of patches for severe vulnerabilities that could facilitate code execution and system takeover via Google Chrome

πŸ“– Read

via "ITPro".
πŸ“’ Data protection policies and procedures πŸ“’

Why your company needs them, and what they should include

πŸ“– Read

via "ITPro".
πŸ“’ Hackers to face 25 years in jail for cyber attacks on Australia's national infrastructure πŸ“’

The proposals aim to update current laws to account for cyber threats like ransomware

πŸ“– Read

via "ITPro".
πŸ“’ Cyber security startups pull in record-breaking investment in 2021 πŸ“’

Data suggests high-profile data breaches led to a greater number of transactions valued at $100 million or more

πŸ“– Read

via "ITPro".
πŸ“’ CISA updates must-patch bug list for federal agencies πŸ“’

Latest collection includes bugs up to seven years old that are still exploited in the wild

πŸ“– Read

via "ITPro".
πŸ“’ Almost a quarter of all spam emails were sent from Russia in 2021 πŸ“’

Last year's spam emails mostly centred around money and investment, Bond and Spider-Man movie premieres, and the pandemic

πŸ“– Read

via "ITPro".
πŸ“’ Juniper acquires cloud networking startup WiteSand πŸ“’

The deal will enable Juniper to advance traditional NAC solutions using AI and the cloud

πŸ“– Read

via "ITPro".
πŸ“’ Ukrainian Ministry of Defence hit by DDoS attack πŸ“’

Ukraine’s largest commercial bank and State Savings Bank were also hit by cyber attacks

πŸ“– Read

via "ITPro".
πŸ“’ Nine tips to improve your disaster recovery strategy πŸ“’

Whether you have a well-rehearsed DR plan in place or are just starting out, here's how to take your strategy to the next level

πŸ“– Read

via "ITPro".
πŸ“’ Remote access to businesses sold for huge profit in growing dark web operation πŸ“’

Researchers told IT Pro the lucrative business model is reaching 'full maturity' but has opportunities to become even more profitable in the near future

πŸ“– Read

via "ITPro".
πŸ“’ Google brings Privacy Sandbox initiative to Android πŸ“’

Multi-year effort likely to bring new Topics API to mobile OS

πŸ“– Read

via "ITPro".
β€Ό CVE-2021-45007 β€Ό

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0685 β€Ό

Use of Out-of-range Pointer Offset in Conda vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23053 β€Ό

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the Ò€œCondition WidgetҀ� element, that allows the injection of malicious JavaScript into the Γ’β‚¬ΛœURLÒ€ℒ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22126 β€Ό

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the Ò€œWeb PageҀ� element, that allows the injection of malicious JavaScript into the Γ’β‚¬ΛœURLÒ€ℒ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25372 β€Ό

Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23848 β€Ό

In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25375 β€Ό

An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23054 β€Ό

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the Ò€œSummary WidgetҀ� element, that allows the injection of malicious JavaScript into the Γ’β‚¬ΛœURLÒ€ℒ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25297 β€Ό

This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0691 β€Ό

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

πŸ“– Read

via "National Vulnerability Database".