πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Developers Increasingly Prioritize Secure Coding πŸ•΄

But "old habits are hard to break," with 48% of developers still shipping code with vulnerabilities.

πŸ“– Read

via "Dark Reading".
⚠ Firefox 99 is out – no major bugs, but update anyway! ⚠

Firefox's four-weekly updates just dropped - here's what you need to know.

πŸ“– Read

via "Naked Security".
⚠ Google’s monthly Android updates patch numerous β€œget root” holes ⚠

Get the update now... if it's available for your phone. Here's how to check.

πŸ“– Read

via "Naked Security".
πŸ•΄ Microsoft Details New Security Features for Windows 11 πŸ•΄

Security features to come include a TPM-like security processor for protecting artifacts that a computer uses during the secure boot-up process, as well as a control for blocking unsigned and untrusted apps.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23446 β€Ό

A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23441 β€Ό

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29013 β€Ό

An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests.

πŸ“– Read

via "National Vulnerability Database".
❌ Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info ❌

Threat actors target Office 365 and Google Workspace in a new campaign, which uses a legitimate domain associated with a road-safety center in Moscow to send messages.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ UK retailer The Works blames store closures on POS problems following cyber-attack πŸ—“οΈ

Discount chain is working to restore stock deliveries

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why XDR As We Know It Will Fail πŸ•΄

Don't take the XDR hype at face value. Do security due diligence and add a connectivity level for data access across all silos for best response.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1253 β€Ό

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1.0.8.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Authorities seize Hydra servers in bust against darknet cybercrime marketplace πŸ—“οΈ

Wretched hive of villainy shut down

πŸ“– Read

via "The Daily Swig".
⚠ Serious Security: Darkweb drugs market Hydra taken offline by German police ⚠

Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-24786 β€Ό

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27108 β€Ό

OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24793 β€Ό

PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.12 and prior affects applications that uses PJSIP DNS resolution. It doesn't affect PJSIP users who utilize an external resolver. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver instead.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27109 β€Ό

OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27110 β€Ό

OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27107 β€Ό

OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Linux Systems Are Becoming Bigger Targets πŸ•΄

To prevent Linux exploits, organizations should establish an integrated security approach that extends to the network edge.

πŸ“– Read

via "Dark Reading".
πŸ•΄ FBI-Led Operation Disrupts Russian GRU Botnet πŸ•΄

"Cyclops Blink" operation disabled firewalls behind the Sandworm hacking team's network of infected victim devices.

πŸ“– Read

via "Dark Reading".