πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-0756 β€Ό

Improper Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical Firefox Zero-Day Bugs Allow RCE, Sandbox Escape ❌

Both vulnerabilities are use-after-free issues in Mozilla's popular web browser.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Fresh flaws in Facebook Canvas earn bug bounty hunter a second payday πŸ—“οΈ

Next-level account takeover

πŸ“– Read

via "The Daily Swig".
❌ Nvidia’s Stolen Code-Signing Certs Used to Sign Malware ❌

Nvidia certificates are being used to sign malware, enabling malicious programs to pose as legitimate and slide past security safeguards on Windows machines.

πŸ“– Read

via "Threat Post".
πŸ•΄ Industrial Systems See More Vulnerabilities, Greater Threat πŸ•΄

The makers of operational technology and connected devices saw reported vulnerabilities grow by half in 2021, but other trends may be more disturbing.

πŸ“– Read

via "Dark Reading".
❌ Samsung Confirms Lapsus$ Ransomware Hit, Source Code Leak ❌

The move comes just a week after GPU-maker NVIDIA was hit by Lapsus$ and every employee credential was leaked.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-38989 β€Ό

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22351 β€Ό

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38988 β€Ό

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212950.

πŸ“– Read

via "National Vulnerability Database".
πŸ” SEC Mulling New Cybersecurity Rules πŸ”

Recently proposed SEC cybersecurity rules could affect how U.S. securities markets, including issuers, registrants, and service providers, approach compliance efforts.

πŸ“– Read

via "".
❌ Novel Attack Turns Amazon Devices Against Themselves ❌

Researchers have discovered how to remotely manipulate the Amazon Echo through its own speakers.

πŸ“– Read

via "Threat Post".
πŸ•΄ Name That Edge Toon: Animal Instincts πŸ•΄

Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google in Talks to Acquire Mandiant πŸ•΄

Last month, Microsoft was interested in buying Mandiant. Now, it's Google that is looking at a deal to boost Google Cloud.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Trio of Vendors Offer Free Services to Organizations at Risk of Russian Cyberattacks πŸ•΄

CrowdStrike, Cloudflare, and Ping Identity have teamed up with tools and services for the healthcare, power, and water industries as a way to quickly bolster their security on several fronts.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24737 β€Ό

HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for further usage. Before 3.1.0, HTTPie didnΓƒΒ’Γ’β€šΒ¬Γ‹Ε“t distinguish between cookies and hosts they belonged. This behavior resulted in the exposure of some cookies when there are redirects originating from the actual host to a third party website. Users are advised to upgrade. There are no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36809 β€Ό

A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Conti Ransomware Group Diaries, Part IV: Cryptocrime β™ŸοΈ

Three stories here last week pored over several years’ worth of internal chat records stolen from the Conti ransomware group, the most profitable ransomware gang in operation today. The candid messages revealed how Conti evaded law enforcement and intelligence agencies, what it was like on a typical day at the Conti office, and how Conti secured the digital weaponry used in their attacks. This final post on the Conti conversations explores different schemes that Conti pursued to invest in and steal cryptocurrencies.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2021-43944 β€Ό

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Breaking the Bias for International Women’s Day 2022 πŸ•΄

The theme of International Women’s Day 2022 is β€œBreak the bias." This is what #BreaktheBias means to me.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 8 More Women in Security You May Not Know But Should πŸ•΄

Dark Reading highlights women who are quietly changing the game in cybersecurity. We also revisit some of those we've spoken to in the past to see what they're up to now.

πŸ“– Read

via "Dark Reading".