πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Microsoft praised for quickly resolving Azure Automation cloud security vulnerability πŸ—“οΈ

Automatic for the people

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-0870 β€Ό

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0871 β€Ό

Improper Authorization in GitHub repository gogs/gogs prior to 0.12.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0928 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 3/11 πŸ”

Why the healthcare industry should invest in cybersecurity, a critical Azure bug fixed, and more - catch up on the infosec news of the week!

πŸ“– Read

via "".
⚠ S3 Ep73: Ransomware with a difference, dirty Linux pipes, and much more [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ—“οΈ UK ferry operator Wightlink flags potential data breach after β€˜highly sophisticated’ cyber-attack πŸ—“οΈ

Personal data potentially compromised, but English Channel crossings unaffected

πŸ“– Read

via "The Daily Swig".
❌ Raccoon Stealer Crawls Into Telegram ❌

The credential-stealing trash panda is using the chat app to store and update C2 addresses as crooks find creative new ways to distribute the malware.

πŸ“– Read

via "Threat Post".
πŸ‘1
β€Ό CVE-2022-21819 β€Ό

NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access to the board direct read/write access to the entire system address space through the PCI bus. Such an attack could result in denial of service, code execution, escalation of privileges, and impact to data integrity and confidentiality. The scope impact may extend to other components.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0860 β€Ό

Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How to Combat the No. 1 Cause of Security Breaches: Complexity πŸ•΄

The scaling of hardware, software and people has created an ever-growing complexity problem.

πŸ“– Read

via "Dark Reading".
⚠ Alleged Kaseya ransomware attacker arrives in Texas for trial ⚠

The US Independence Day weekend of 2021 wasn't much of a holiday for cybersecurity staff. That was when the Kaseya attack unfolded...

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Stats widget hacked in attempt to breach Russian government agency websites πŸ—“οΈ

The software was reportedly used as part of a short-lived software supply chain attack

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-44618 β€Ό

A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0932 β€Ό

Improper Authorization in GitHub repository saleor/saleor prior to 3.1.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44620 β€Ό

A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Report: Recent 10x Increase in Cyberattacks on Ukraine β™ŸοΈ

As their cities suffered more intense bombardment by Russian military forces this week, Ukrainian Internet users came under renewed cyberattacks, with one Internet company providing service there saying they blocked ten times the normal number of phishing and malware attacks targeting Ukrainians.

πŸ“– Read

via "Krebs on Security".
❌ Russia Issues Its Own TLS Certs ❌

The country’s citizens are being blocked from the internet because foreign certificate authorities can't accept payments due to Ukraine-related sanctions, so it created its own CA.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-26401 β€Ό

LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24095 β€Ό

Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23930 β€Ό

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

πŸ“– Read

via "National Vulnerability Database".