π’ The new rules of ransomware π’
π Read
via "ITPro".
The rise in working from home has brought with it a rise in ransomware attacks, but an effective backup routine can guard against disasterπ Read
via "ITPro".
IT PRO
The new rules of ransomware | IT PRO
The rise in working from home has brought with it a rise in ransomware attacks, but an effective backup routine can guard against disaster
π’ Microsoft releases Defender for Azure Cosmos DB in preview π’
π Read
via "ITPro".
The database protection service is exclusive to Microsoft Defender for Cloud usersπ Read
via "ITPro".
ITPro
Microsoft releases Defender for Azure Cosmos DB in preview
The database protection service is exclusive to Microsoft Defender for Cloud users
π’ Anonymous hacks website of Russian Space Research Institute π’
π Read
via "ITPro".
Russiaβs lunar missions files were obtained through a brute-force attack on a private service hosted by Roscosmosπ Read
via "ITPro".
IT PRO
Anonymous hacks website of Russian Space Research Institute | IT PRO
Russiaβs lunar missions files were obtained through a brute-force attack on a private service hosted by Roscosmos
π’ Cisco patches critical bugs in collaboration products π’
π Read
via "ITPro".
Attackers could exploit the flaw to run their own code on Cisco's video conferencing serversπ Read
via "ITPro".
IT PRO
Cisco patches critical bugs in collaboration products | IT PRO
Attackers could exploit the flaw to run their own code on Cisco's video conferencing servers
π’ IT Pro News In Review: Compromised Nvidia data, protesters boycott Russian tech, Conti data breach π’
π Read
via "ITPro".
Catch up on the biggest headlines of the week in just two minutesπ Read
via "ITPro".
IT PRO
IT Pro News In Review: Compromised Nvidia data, protesters boycott Russian tech, Conti data breach
Catch up on the biggest headlines of the week in just two minutes
π’ OneWeb suspends satellite launch from Russian spaceport π’
π Read
via "ITPro".
The decision follows Roscosmosβ demand that the UK sell its 20% stake in OneWeb purchased in 2020π Read
via "ITPro".
IT PRO
OneWeb suspends satellite launch from Russian spaceport | IT PRO
The decision follows Roscosmosβ demand that the UK sell its 20% stake in OneWeb purchased in 2020
π1
βΌ CVE-2022-25069 βΌ
π Read
via "National Vulnerability Database".
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25465 βΌ
π Read
via "National Vulnerability Database".
Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25044 βΌ
π Read
via "National Vulnerability Database".
Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0849 βΌ
π Read
via "National Vulnerability Database".
Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.π Read
via "National Vulnerability Database".
β Firefox patches two in-the-wild exploits β update now! β
π Read
via "Naked Security".
Firefox just published a double-zero-day patch - "remote code execution" combined with "sandbox escape". Update now!π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
βΌ CVE-2022-26487 βΌ
π Read
via "National Vulnerability Database".
Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allow remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic).π Read
via "National Vulnerability Database".
π1
βΌ CVE-2022-26490 βΌ
π Read
via "National Vulnerability Database".
st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0868 βΌ
π Read
via "National Vulnerability Database".
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44748 βΌ
π Read
via "National Vulnerability Database".
A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger universal cross-site scripting through the browser. User interaction is required prior to exploitation, such as entering a malicious website to trigger the vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44749 βΌ
π Read
via "National Vulnerability Database".
A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful exploitation may lead to arbitrary code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0697 βΌ
π Read
via "National Vulnerability Database".
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.π Read
via "National Vulnerability Database".
βΌ CVE-2021-4199 βΌ
π Read
via "National Vulnerability Database".
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146.π Read
via "National Vulnerability Database".
βΌ CVE-2021-4198 βΌ
π Read
via "National Vulnerability Database".
A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product processes and generate crashdump files. This issue affects: Bitdefender Total Security versions prior to 26.0.3.29. Bitdefender Internet Security versions prior to 26.0.3.29. Bitdefender Antivirus Plus versions prior to 26.0.3.29. Bitdefender Endpoint Security Tools versions prior to 7.2.2.92. Bitdefender VPN Standalone versions prior to 25.5.0.48.π Read
via "National Vulnerability Database".
π΄ After a Busy December, Attacks on Log4J Vulnerability Dropped π΄
π Read
via "Dark Reading".
While attackers and researchers shift their attention to the next new vulnerability, security teams make sure they finish patching vulnerable Log4j versions in their applications and services .π Read
via "Dark Reading".
Dark Reading
After a Busy December, Attacks on Log4j Vulnerability Dropped
While attackers and researchers shift their attention to the next new vulnerability, security teams make sure they finish patching vulnerable Log4j versions in their applications and services.
ποΈ Utah privacy bill places tighter controls on consumer data ποΈ
π Read
via "The Daily Swig".
Policymakers move forward with new data privacy legislationπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Utah privacy bill places tighter controls on consumer data
Policymakers move forward with new data privacy legislation