πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Hackers spotted using CAPTCHAs to dodge email security scanners πŸ“’

The technique allows hackers to hide malicious links in HTML files

πŸ“– Read

via "ITPro".
πŸ“’ Okta confirms investigation into alleged LAPSUS$ security breach πŸ“’

Businesses are now on high alert as the hackers claim to have had full admin access to the back-end of identity and authentication provider Okta for at least two months

πŸ“– Read

via "ITPro".
πŸ“’ Ransomware strikes Scottish mental health charity πŸ“’

The RansomEXX cyber criminals have claimed responsibility for the hack which led to more than 12GB of sensitive data being leaked to the dark web

πŸ“– Read

via "ITPro".
πŸ“’ EU and US reach agreement on Privacy Shield replacement πŸ“’

Privacy campaigner Max Schrems suggests the deal amounts to a "patchwork approach" that will ultimately fail

πŸ“– Read

via "ITPro".
πŸ“’ McAfee Enterprise’s SSE business rebrands to Skyhigh Security πŸ“’

The new organisation will provide a β€œcomprehensive and converged” approach to data security, Symphony Technology Group says

πŸ“– Read

via "ITPro".
πŸ“’ Open source dev attacked for spreading data-wiping 'protestware' πŸ“’

Developer denies wiping users' drives in spite of detailed code analysis

πŸ“– Read

via "ITPro".
πŸ“’ Biden urges US businesses to prepare for Russian cyber attacks πŸ“’

The president has urged critical infrastructure owners to accelerate efforts to lock their digital doors

πŸ“– Read

via "ITPro".
πŸ‘Ž1
πŸ“’ How to secure business printers πŸ“’

Your office printer is a juicy target for hackers, so what can you do to secure it?

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft Defender drops "downpour" of false ransomware alerts on customers πŸ“’

System administrators made numerous reports of false-positive results being flagged for seemingly innocuous files and behaviours on Wednesday

πŸ“– Read

via "ITPro".
πŸ“’ Avast to acquire identity services provider SecureKey πŸ“’

The acquisition will add to Avast’s privacy-focused identity product and services portfolio

πŸ“– Read

via "ITPro".
πŸ“’ Western Digital flaw allows hackers to access restricted files πŸ“’

The proprietary file explorer app contained directory traversal bug, says storage vendor

πŸ“– Read

via "ITPro".
πŸ“’ Google exposes 'uniquely personal' access broker behind worst Conti, FIN12 ransomware attacks πŸ“’

Investigation unveils the inner workings of one access broker that helped two of the most-hated ransomware gangs in history

πŸ“– Read

via "ITPro".
πŸ“’ IBM launches multi-cloud key management service πŸ“’

Unified Key Orchestrator will control keys on cloud and on-premises environments

πŸ“– Read

via "ITPro".
πŸ“’ Unified endpoint management solutions 2021-22 πŸ“’

Analysing the UEM landscape

πŸ“– Read

via "ITPro".
πŸ“’ The Total Economic Impactβ„’ of IBM Security MaaS360 with Watson πŸ“’

Cost savings and business benefits enabled by MaaS360

πŸ“– Read

via "ITPro".
πŸ“’ What is cloud ransomware and how can you avoid attacks? πŸ“’

With ransomware increasingly targeting cloud applications and data, as well as cloud-based companies, we explain how you can protect your business

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-26252 β€Ό

aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26254 β€Ό

WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44127 β€Ό

In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26598 β€Ό

ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26273 β€Ό

EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

πŸ“– Read

via "National Vulnerability Database".