πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1534 β€Ό

Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Data breach at US healthcare provider ARcare impacts 345,000 individuals πŸ—“οΈ

Sensitive medical and other personal data was potentially exposed

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Ambient.ai Expands Computer Vision Capabilities for Better Building Security πŸ•΄

The AI startup releases new threat signatures to expand the computer vision platform’s ability to identify potential physical security incidents from camera feeds.

πŸ“– Read

via "Dark Reading".
πŸ›  TOR Virtual Network Tunneling Tool 0.4.7.7 πŸ› 

Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs). This is the source code release.

πŸ“– Read

via "Packet Storm Security".
❌ Security Turbulence in the Cloud: Survey Says… ❌

Exclusive Threatpost research examines organizations’ top cloud security concerns, attitudes towards zero-trust and DevSecOps.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-1536 β€Ό

A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44596 β€Ό

Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to execute malicious executable without any validation from a remote location and gain SYSTEM privileges

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44595 β€Ό

Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41942 β€Ό

The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Take a Diversified Approach to Encryption πŸ•΄

Encryption will break, so it's important to mix and layer different encryption methods.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep80: Ransomware news, phishing woes, NAS bugs, and a giant hole in Java [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Bug Bounty Radar // The latest bug bounty programs for May 2022 πŸ—“οΈ

New web targets for the discerning hacker

πŸ“– Read

via "The Daily Swig".
πŸ“’ IT Pro News in Review: Vulnerable Lenovo laptops, record EE 5G speeds, Okta ends LAPSUS$ probe πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ“’ DDoS attacks surge to record numbers in 2022 as a result of Russia-Ukraine war πŸ“’

Cases this year saw some of the longest-lasting DDoS attacks ever seen as hacktivists assembled to take on their enemies in the ongoing cyber war between Russia and Ukraine

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ Encryption battle plays out in Australian Parliament πŸ“’

The opposition said that the government is β€œaddicted to secrecy”

πŸ“– Read

via "ITPro".
πŸ“’ Best VPN services 2022 πŸ“’

With remote working on the rise, we round up the best tried and tested VPN services

πŸ“– Read

via "ITPro".
πŸ“’ AWS launches quantum random number generator πŸ“’

The cloud giant is using an Australian university’s technology to help customers access random numbers for experiments through an API

πŸ“– Read

via "ITPro".
πŸ“’ Exclusive: Former Shiseido staff say company was aware of data breach weeks before official notice πŸ“’

Fake companies were created using the stolen identities of hundreds of Shiseido employees, former staff claim

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft announces lucrative new bug bounty awards for M365 products and services πŸ“’

The new awards will focus on scenario-based weaknesses and offer bonuses of up to 30% for the most severe bugs

πŸ“– Read

via "ITPro".
πŸ“’ Funky Pigeon site offline after "cyber incident" πŸ“’

The WH Smith-owned card site has reported the breach to "the relevant regulators"

πŸ“– Read

via "ITPro".
πŸ“’ Tech leaders share how to break into the tech industry πŸ“’

β€œYou have to feel like a true member of the IT world before you actually become a member"

πŸ“– Read

via "ITPro".