πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24741 β€Ό

Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud Server is upgraded to 21.0.8 , 22.2.4 or 23.0.1. Users unable to upgrade should disable preview generation with the `'enable_previews'` config flag.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24734 β€Ό

MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change Settings_ pages. This results in a Remote Code Execution (RCE) vulnerability. The vulnerable module requires Admin CP access with the `Can manage settings?` permission. MyBB's Settings module, which allows administrators to add, edit, and delete non-default settings, stores setting data in an options code string ($options_code; mybb_settings.optionscode database column) that identifies the setting type and its options, separated by a new line character (\n). In MyBB 1.2.0, support for setting type php was added, for which the remaining part of the options code is PHP code executed on Change Settings pages (reserved for plugins and internal use). MyBB 1.8.30 resolves this issue. There are no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0890 β€Ό

NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38296 β€Ό

Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Middleboxes now being used for DDoS attacks in the wild, Akamai finds πŸ—“οΈ

Malicious actors are starting to add TCP middlebox reflection to their arsenal

πŸ“– Read

via "The Daily Swig".
❌ Qakbot Botnet Sprouts Fangs, Injects Malware into Email Threads ❌

The ever-shifting, ever-more-powerful malware is now hijacking email threads to download malicious DLLs that inject password-stealing code into webpages, among other foul things.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-0895 β€Ό

Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ What Security Controls Do I Need for My Kubernetes Cluster? πŸ•΄

This Tech Tip offers some security controls to embed in your organization's CI/CD pipeline to protect Kubernetes clusters and corporate networks.

πŸ“– Read

via "Dark Reading".
❌ Multi-Ransomwared Victims Have It Coming–Podcast ❌

Let's blame the victim. IT decision makers' confidence about security doesn't jibe with their concession that repeated incidents are their own fault, says ExtraHop's Jamie Moles.

πŸ“– Read

via "Threat Post".
πŸ” RagnarLocker Ransomware Connected to Hacks at 52 Organizations πŸ”

New guidance from the FBI contains IOCs and technical details on how the ransomware spreads.

πŸ“– Read

via "".
❌ Russia May Use Ransomware Payouts to Avoid Sanctions ❌

FinCEN warns financial institutions to beware of unusual cryptocurrency payments or illegal transactions Russia may use to evade restrictions imposed due to its invasion of Ukraine.

πŸ“– Read

via "Threat Post".
πŸ•΄ Log4j and Livestock Apps: APT41 Wages Persistent Cyberattack Campaign on US Government πŸ•΄

The group's attack methods have included exploits for a zero-day vulnerability in a livestock-tracking apps as well as for the Apache Log4 flaw.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ 1Password increases bug bounty reward to $1 million πŸ—“οΈ

Researchers offered record incentive for vulnerabilities found on Bugcrowd programs

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why You Should Be Using CISA's Catalog of Exploited Vulns πŸ•΄

It's a great starting point for organizations that want to ride the wave of risk-based vulnerability management rather than drowning beneath it.

πŸ“– Read

via "Dark Reading".
❌ Most Orgs Would Take Security Bugs Over Ethical Hacking Help ❌

A new survey suggests that security is becoming more important for enterprises, but they’re still falling back on old "security by obscurity" ways.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ RagnarLocker ransomware struck 52 critical infrastructure entities within two years – FBI πŸ—“οΈ

Agency issues mitigation advice to help organizations tighten network defenses

πŸ“– Read

via "The Daily Swig".
πŸ‘1
⚠ S3 Ep73: Ransomware with a difference, dirty Linux pipes, and much more [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-0905 β€Ό

Improper Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0906 β€Ό

Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Falco 0.31.1 πŸ› 

Sysdig Falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Cyber Insurance and Business Risk: How the Relationship Is Changing Reinsurance & Policy Guidance πŸ•΄

While cyber insurance will continue to exist, it will cost more and cover less β€” and that's changing the risk your company faces.

πŸ“– Read

via "Dark Reading".