πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-27373 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27375 β€Ό

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27818 β€Ό

SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.

πŸ“– Read

via "National Vulnerability Database".
⚠ Serious Security: Darkweb drugs market Hydra taken offline by German police ⚠

Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...

πŸ“– Read

via "Naked Security".
❀1πŸ‘1
⚠ S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast] ⚠

Latest episode - listen now! Cybersecurity news and advice in plain English.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-46416 β€Ό

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23900 β€Ό

A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46417 β€Ό

Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
❌ MacOS Malware: Myth vs. Truth – Podcast ❌

Huntress Labs R&D Director Jamie Levy busts the old β€œMacs don’t get viruses” myth and offers tips on how MacOS malware differs and how to protect against it.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Apple paid out $36,000 bug bounty for HTTP request smuggling flaws on core web apps – research πŸ—“οΈ

Queue poisoning attacks allegedly put accounts at risk of takeover

πŸ“– Read

via "The Daily Swig".
πŸ•΄ The Blurring Line, and Growing Risk, Between Physical and Digital Supply Chains πŸ•΄

Risk increases as the lines between physical and digital supply chains blur and the computing footprint expands.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Nearly Two-Thirds of Organizations Hit with Ransomware Paid Up in 2021 πŸ•΄

CyberEdge report contains data on the skills shortage, the hottest security tech in 2022, the weakest links of the year, specialty certifications in demand, and more.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Blumira Unveils Cloud SIEM With Integrated Detection and Response for SMBs πŸ•΄

Self-service cloud SIEM comes in free and paid editions.

πŸ“– Read

via "Dark Reading".
❌ SSRF Flaw in Fintech Platform Allowed for Compromise of Bank Accounts ❌

Researchers discovered the vulnerability in an API already integrated into many bank systems, which could have defrauded millions of users by giving attackers access to their funds.

πŸ“– Read

via "Threat Post".
πŸ‘1
πŸ—“οΈ Wake-up call: Is the infosec skills gap causing a mental health crisis? πŸ—“οΈ

Increasing workloads are causing depression and anxiety among frontline security staff, report claims

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2021-46418 β€Ό

An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-46419 β€Ό

An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ Keysight Delivers Zero Trust Test Solution πŸ•΄

Enables network equipment manufacturers to validate devices in distributed cloud networks.

πŸ“– Read

via "Dark Reading".
πŸ‘2
πŸ—“οΈ VMware patches critical flaws in Workspace ONE Access identity management software πŸ—“οΈ

Virtual reality

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Nord Security Raises First Outside Capital at $1.6B Valuation πŸ•΄

Financing raised from Novator Ventures, Burda Principal Investments, General Catalyst, and leading angel investors.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-27016 β€Ό

There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.

πŸ“– Read

via "National Vulnerability Database".