πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ US healthcare data breach impacts 85,000 law enforcement officers πŸ—“οΈ

Law Enforcement Health Benefits was hit by a ransomware attack last year

πŸ“– Read

via "The Daily Swig".
πŸ‘2
β€Ό CVE-2022-24136 β€Ό

Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1176 β€Ό

Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Critical SQL injection flaw fixed in Rapid7’s Nexpose vulnerability scanner πŸ—“οΈ

Attacks could be mounted via manipulation of query operators in search criteria

πŸ“– Read

via "The Daily Swig".
❌ A Blockchain Primer and a Bored Ape Headscratcher – Podcast ❌

Mystified? Now’s the time to learn about cryptocurrency-associated risks: Listen to KnowBe4’s Dr. Lydia Kostopoulos explain blockchain, NFTs and how to stay safe.

πŸ“– Read

via "Threat Post".
πŸ•΄ Nation-State Hackers Ramp Up Ukraine War-Themed Attacks πŸ•΄

Among them is the operator of the Ghostwriter misinformation campaign, with a new browser-in-browser phishing technique, according to Google's research team.

πŸ“– Read

via "Dark Reading".
❌ QNAP Customers Adrift, Waiting on Fix for OpenSSL Bug ❌

QNAP is warning clients that a recently disclosed vulnerability affects most of its NAS devices, with no mitigation available while the vendor readies a patch.

πŸ“– Read

via "Threat Post".
⚠ World Backup Day: 5 data recovery tips for everyone! ⚠

The only backup you will ever regret is the one you didn't make

πŸ“– Read

via "Naked Security".
πŸ‘1
⚠ S3 Ep76: Deadbolt, LAPSUS$, Zlib, and a Chrome 0-day [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
⚠ β€œVMware Spring Cloud” Java bug gives instant remote code execution – update now! ⚠

Easy unauthenticated remote code execution - PoC code already out

πŸ“– Read

via "Naked Security".
πŸ•΄ Protecting Your Organization Against a New Class of Cyber Threats: HEAT πŸ•΄

Take a preventative threat approach and apply security measures near end users, applications, and data to increase protection.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Spring4Shell: Spring users face new, zero-day vulnerability πŸ—“οΈ

Both security bugs are now reportedly being exploited in the wild

πŸ“– Read

via "The Daily Swig".
❌ Automaker Cybersecurity Lagging Behind Tech Adoption, Experts Warn ❌

A bug in Honda is indicative of the sprawling car-attack surface that could give cyberattackers easy access to victims, as global use of β€˜smart car tech’ and EVs surges.

πŸ“– Read

via "Threat Post".
πŸ” U.S. Election Officials Targeted in Phishing Campaign πŸ”

The campaign is part of what the FBI calls "a concerted effort to target US election officials."

πŸ“– Read

via "".
⚠ Two different β€œVMware Spring” bugs at large – we cut through the confusion ⚠

Whoever came up with the name "Spring4Shell" didn't help at all... we cut through the Spring Bug confusion

πŸ“– Read

via "Naked Security".
❌ Belarusian β€˜Ghostwriter’ Actor Picks Up BitB for Ukraine-Related Attacks ❌

Ghostwriter is one of 3 campaigns using war-themed attacks, with cyber-fire coming in from government-backed actors in China, Iran, North Korea & Russia.

πŸ“– Read

via "Threat Post".
πŸ•΄ U.S. Cyber Command Adds APUS as Member in Newly Formed Academic Network πŸ•΄

The Academic Engagement Network is designed to advance cybersecurity in four areas.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-34257 β€Ό

Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0350 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43506 β€Ό

An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43505 β€Ό

Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.

πŸ“– Read

via "National Vulnerability Database".