πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ NordPass teams up with insurance provider Cowbell Cyber to improve security awareness πŸ“’

Policy holders will be eligible for a 15% discount on NordPass Business

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-0736 β€Ό

Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Google Groups unsubscribe feature abused to remove members without consent πŸ—“οΈ

β€˜This could have destroyed the Google Payment system flow,’ security researcher tells The Daily Swig

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-0724 β€Ό

Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0719 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0721 β€Ό

Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ India’s Personal Data Privacy Bill: What does it mean for individuals and businesses? πŸ—“οΈ

New legislation sets out to bring India in line with international best practice, but what will this look like in action?

πŸ“– Read

via "The Daily Swig".
πŸ›  OpenSSH 8.9p1 πŸ› 

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2022-0727 β€Ό

Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0726 β€Ό

Improper Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0729 β€Ό

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Why Passwordless Is at an Impasse πŸ•΄

Many widely used business applications aren't built to support passwordless login because identity and authentication remain siloed.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ransomware Trained on Manufacturing Firms Led Cyberattacks in Industrial Sector πŸ•΄

Meanwhile, a few "alarming" infiltrations of OT networks by previously unknown threat groups occurred last year as well.

πŸ“– Read

via "Dark Reading".
❌ Creaky Old WannaCry, GandCrab Top the Ransomware Scene ❌

Nothing like zombie campaigns: WannaCry's old as dirt, and GandCrab threw in the towel years ago. They're on auto-pilot at this point, researchers say.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ EU countries offer cyber-defense assistance to Ukraine πŸ—“οΈ

Increase in cyber-attacks expected to accompany further incursions into Ukrainian territory

πŸ“– Read

via "The Daily Swig".
❌ Sextortion Rears Its Ugly Head Again ❌

Attackers are sending email blasts with malware links in embedded PDFs as a way to evade email filters, lying about having fictional "video evidence."

πŸ“– Read

via "Threat Post".
πŸ•΄ Microsoft Debuts Unified Service for Multicloud ID Management πŸ•΄

With nine in 10 companies adopting a multicloud strategy, service providers are focused on finding ways to support the management and security efforts of businesses that rely on multiple cloud resources.

πŸ“– Read

via "Dark Reading".
⚠ WordPress backup plugin maker Updraft says β€œYou should update”… ⚠

A straight-talking bug report written in plain English by an actual expert - there's a teachable moment in this cybersecurity story!

πŸ“– Read

via "Naked Security".
⚠ Apple AirTag anti-stalking protection bypassed by researchers ⚠

Problems with Apple's Tracker Detect system, which warns you of likely stalking attempts using hidden AirTags.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-20625 β€Ό

A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol messages that are processed by the Cisco Discovery Protocol service. An attacker could exploit this vulnerability by sending a series of malicious Cisco Discovery Protocol messages to an affected device. A successful exploit could allow the attacker to cause the Cisco Discovery Protocol service to fail and restart. In rare conditions, repeated failures of the process could occur, which could cause the entire device to restart.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20650 β€Ό

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default.

πŸ“– Read

via "National Vulnerability Database".