πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Biden urges US businesses to prepare for Russian cyber attacks πŸ“’

The president has urged critical infrastructure owners to accelerate efforts to lock their digital doors

πŸ“– Read

via "ITPro".
πŸ‘Ž1
πŸ“’ How to secure business printers πŸ“’

Your office printer is a juicy target for hackers, so what can you do to secure it?

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft Defender drops "downpour" of false ransomware alerts on customers πŸ“’

System administrators made numerous reports of false-positive results being flagged for seemingly innocuous files and behaviours on Wednesday

πŸ“– Read

via "ITPro".
πŸ“’ Avast to acquire identity services provider SecureKey πŸ“’

The acquisition will add to Avast’s privacy-focused identity product and services portfolio

πŸ“– Read

via "ITPro".
πŸ“’ Western Digital flaw allows hackers to access restricted files πŸ“’

The proprietary file explorer app contained directory traversal bug, says storage vendor

πŸ“– Read

via "ITPro".
πŸ“’ Google exposes 'uniquely personal' access broker behind worst Conti, FIN12 ransomware attacks πŸ“’

Investigation unveils the inner workings of one access broker that helped two of the most-hated ransomware gangs in history

πŸ“– Read

via "ITPro".
πŸ“’ IBM launches multi-cloud key management service πŸ“’

Unified Key Orchestrator will control keys on cloud and on-premises environments

πŸ“– Read

via "ITPro".
πŸ“’ Unified endpoint management solutions 2021-22 πŸ“’

Analysing the UEM landscape

πŸ“– Read

via "ITPro".
πŸ“’ The Total Economic Impactβ„’ of IBM Security MaaS360 with Watson πŸ“’

Cost savings and business benefits enabled by MaaS360

πŸ“– Read

via "ITPro".
πŸ“’ What is cloud ransomware and how can you avoid attacks? πŸ“’

With ransomware increasingly targeting cloud applications and data, as well as cloud-based companies, we explain how you can protect your business

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-26252 β€Ό

aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26254 β€Ό

WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44127 β€Ό

In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26598 β€Ό

ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26273 β€Ό

EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45491 β€Ό

3CX System through 2022-03-17 stores cleartext passwords in a database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44208 β€Ό

OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26268 β€Ό

Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26599 β€Ό

ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24303 β€Ό

Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26600 β€Ό

ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).

πŸ“– Read

via "National Vulnerability Database".