πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25596 β€Ό

ASUS RT-AC56UÒ€ℒs configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43430 β€Ό

An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26675 β€Ό

aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23970 β€Ό

ASUS RT-AX56UÒ€ℒs update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Scan This: There's Danger in QR Codes πŸ•΄

Trendy restaurant tables now feature QR codes that lead to menus, payment apps, and CISO nightmares.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ukrainian Member of Notorious FIN7 Cybercrime Group Sentenced πŸ•΄

Denys Iarmak is the third member of FIN7 to go to prison.

πŸ“– Read

via "Dark Reading".
πŸ•΄ BlackCat Purveyor Shows Ransomware Operators Have Nine Lives πŸ•΄

Members of BlackMatter, and possibly REvil, have likely resurfaced in the new ransomware-as-a-service group ALPHV, whose primary tool is the BlackCat malware.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-36202 β€Ό

Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43453 β€Ό

A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c file. This issue is similar to CVE-2020-29657.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ SeeMetrics to Help CISOs Measure Security Success πŸ•΄

The company makes cybersecurity performance management software to quantify how well cyber-risk solutions are actually working.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Mandiant to Use CrowdStrike Technology in Its Incident Response Services πŸ•΄

Collaboration between the two firms will help organizations better identify and protect against complexity cyberthreats, chief executives from both companies said.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Actions Target Russian Govt. Botnet, Hydra Dark Market β™ŸοΈ

The U.S. Federal Bureau of Investigation (FBI) says it has disrupted a giant botnet built and operated by a Russian government intelligence unit known for launching destructive cyberattacks against energy infrastructure in the United States and Ukraine. Separately, law enforcement agencies in the U.S. and Germany moved to decapitate "Hydra," a billion-dollar Russian darknet drug bazaar that also helped to launder the profits of multiple Russian ransomware groups.

πŸ“– Read

via "Krebs on Security".
πŸ‘1
β€Ό CVE-2021-43474 β€Ό

An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24681 β€Ό

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Jack Dorsey admits regret for helping to centralise the internet πŸ“’

The former Twitter CEO took to the platform he founded to express regret at the 'damaging' development of the internet

πŸ“– Read

via "ITPro".
πŸ“’ No 10 urges gov and businesses to β€œact as one” against Russian cyber attacks πŸ“’

No 10 Chief of Staff and Chancellor of the Steve Barclay warned of a β€œheightened risk of hostile cyber activity” coming from Russian hackers

πŸ“– Read

via "ITPro".
πŸ“’ Bring insights and data closer to customers with edge computing πŸ“’

How to innovate, make faster decisions and provide engaging experiences

πŸ“– Read

via "ITPro".
πŸ“’ Auvik Network Management review: A breeze to deploy πŸ“’

Auvik’s cloud-hosted monitoring is quick to provide a complete picture of your network

πŸ“– Read

via "ITPro".
πŸ“’ Is Kaspersky still safe to use? πŸ“’

Western nations have, once again, warned against using the Russian cyber security firm's products, but how reasonable are their claims?

πŸ“– Read

via "ITPro".
πŸ“’ New MFA security standards for online payments come into force πŸ“’

Version 4.0 of PCI DSS also reforms password requirements and broadens its terminology to address other network access controls

πŸ“– Read

via "ITPro".
πŸ“’ The Total Economic Impactβ„’ of IBM Security MaaS360 with Watson πŸ“’

Cost savings and business benefits enabled by MaaS360

πŸ“– Read

via "ITPro".