πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Russian cyber attacks on Ukraine: What we know so far πŸ“’

A score of additional attacks on the Ukrainian government and other critical services have been reported this week, as Russia officially declares war on the country

πŸ“– Read

via "ITPro".
πŸ“’ Darktrace acquires attack surface management startup Cybersprint πŸ“’

The €47.5 million deal marks Darktrace’s first acquisition in its nine-year history

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ WatchGuard Firebox M290 review: Stiff security at a great price πŸ“’

The Firebox M290 delivers an incredible range of gateway security measures priced right for SMBs

πŸ“– Read

via "ITPro".
πŸ“’ IT Pro 20/20: The new frontier of innovation πŸ“’

Businesses are putting green tech at their heart of their buying decisions, and manufacturers and paying attention

πŸ“– Read

via "ITPro".
πŸ“’ Benefits of AI and machine learning for cloud security πŸ“’

AI and machine learning may not be a silver bullet, but they can still play an important part in cloud security strategies

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft releases new security controls for multi-cloud customers πŸ“’

Tech giant adds Google Cloud protections for Defender for Cloud and CloudKnox Permission management

πŸ“– Read

via "ITPro".
πŸ“’ IRS lets taxpayers bypass facial recognition with virtual interviews πŸ“’

The temporary solution will be in effect through the 2022 tax filing season

πŸ“– Read

via "ITPro".
πŸ“’ How to encrypt files and folders in Windows 10 πŸ“’

Here’s how to make your sensitive data unreadable to prying eyes

πŸ“– Read

via "ITPro".
πŸ“’ ICS and OT vulnerabilities more than doubled in 2021 πŸ“’

One in four flaws found in industrial systems had no patch, Dragos report finds

πŸ“– Read

via "ITPro".
πŸ“’ GitHub goes open source on security research πŸ“’

Community members, enthusiasts, researchers, and academics are now able to submit their own research to widen the understanding of security vulnerabilities

πŸ“– Read

via "ITPro".
πŸ“’ 100 million Samsung Galaxy devices vulnerable to cryptographic key hack πŸ“’

Widespread flaws in hardware-backed key management could enable hackers to bypass FIDO2 authentication

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-25094 β€Ό

Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25095 β€Ό

Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25096 β€Ό

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21706 β€Ό

Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack where an invitation created in one organization (potentially as a role with elevated permissions) can be used to join any other organization. This bypasses any restrictions on required domains on users' email addresses, may be used to gain access to organizations which are only accessible by invitation, and may be used to gain access with elevated privileges. This issue has been patched in release 4.10. There are no known workarounds for this issue. ### Patches _Has the problem been patched? What versions should users upgrade to?_ ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ ### References _Are there any links users can visit to find out more?_ ### For more information If you have any questions or comments about this advisory, you can discuss them on the [developer community Zulip server](https://zulip.com/developer-community/), or email the [Zulip security team](mailto:security@zulip.com).

πŸ“– Read

via "National Vulnerability Database".
πŸ‘2
β€Ό CVE-2022-0762 β€Ό

Business Logic Errors in GitHub repository microweber/microweber prior to 1.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0763 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0764 β€Ό

Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27958 β€Ό

The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26146 β€Ό

Tricentis qTest before 10.4 allows stored XSS by an authenticated attacker.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26149 β€Ό

MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.

πŸ“– Read

via "National Vulnerability Database".