πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Best VPN services 2022 πŸ“’

With remote working on the rise, we round up the best tried and tested VPN services

πŸ“– Read

via "ITPro".
πŸ“’ AWS launches quantum random number generator πŸ“’

The cloud giant is using an Australian university’s technology to help customers access random numbers for experiments through an API

πŸ“– Read

via "ITPro".
πŸ“’ Exclusive: Former Shiseido staff say company was aware of data breach weeks before official notice πŸ“’

Fake companies were created using the stolen identities of hundreds of Shiseido employees, former staff claim

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft announces lucrative new bug bounty awards for M365 products and services πŸ“’

The new awards will focus on scenario-based weaknesses and offer bonuses of up to 30% for the most severe bugs

πŸ“– Read

via "ITPro".
πŸ“’ Funky Pigeon site offline after "cyber incident" πŸ“’

The WH Smith-owned card site has reported the breach to "the relevant regulators"

πŸ“– Read

via "ITPro".
πŸ“’ Tech leaders share how to break into the tech industry πŸ“’

β€œYou have to feel like a true member of the IT world before you actually become a member"

πŸ“– Read

via "ITPro".
πŸ“’ Five Eyes nations warn against impending Russian cyber attacks πŸ“’

Eight hacking groups have reportedly pledged allegiance to the Russian government, according to latest findings from the US, Australian, Canadian, New Zealand, and UK cyber authorities

πŸ“– Read

via "ITPro".
πŸ“’ Vulnerable infrastructure operators are 'switching off' security to avoid downtime πŸ“’

Out-of-date systems are vulnerable to cyber attacks and lack purpose-built products to adequately protect them

πŸ“– Read

via "ITPro".
πŸ“’ Recommendations for managing AI risks πŸ“’

Integrate your external AI tool findings into your broader security programs

πŸ“– Read

via "ITPro".
πŸ“’ Report: UK businesses are less secure when using police-endorsed cyber security tool πŸ“’

The cyber security researcher found the developer of the free software to be "incompetent" and the myriad flaws in the cyber crime-fighting monitoring tool left businesses more at risk of cyber attacks

πŸ“– Read

via "ITPro".
πŸ“’ ConnectWise unveils new incident response service πŸ“’

New offering provides an β€œimmediate lifeline” to a team of cyber experts in the event of a security breach

πŸ“– Read

via "ITPro".
πŸ“’ REvil ransomware group's infrastructure comes back online hinting at fresh campaign πŸ“’

The ransomware gang's old deep web infrastructure is now redirecting to a new website with new victims

πŸ“– Read

via "ITPro".
πŸ“’ The Total Economic Impactβ„’ of Mimecast πŸ“’

Cost savings and business benefits enabled by using Mimecast with Microsoft 365

πŸ“– Read

via "ITPro".
πŸ“’ FBI warns Rust-based ransomware has breached over 60 organisations πŸ“’

The agency has issued an alert warning that the new ransomware has impacted at least 60 global organisations since last November

πŸ“– Read

via "ITPro".
πŸ“’ BT and Toshiba address QKD concerns with new trial πŸ“’

The National Cyber Security Centre (NCSC) previously raised concerns of potential attacks

πŸ“– Read

via "ITPro".
πŸ“’ Qualcomm and Mediatek flaws left millions of Android users at risk πŸ“’

An open source audio codec used by chipset firms is believed to have put two-thirds of Android users' private calls and files at risk

πŸ“– Read

via "ITPro".
πŸ“’ What is the LAPSUS$ group and who is behind the criminal operation? πŸ“’

The most prolific cyber criminals of 2022 have largely evaded identification for months despite being anything but secretive in the way they work

πŸ“– Read

via "ITPro".
⚠ GitHub issues final report on supply-chain source code intrusions ⚠

Learn how to find out which apps you've given access rights to, and how to revoke those rights immediately in an emergency.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-41948 β€Ό

A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24900 β€Ό

Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When the `os.path.join` call encounters an absolute path, it ignores all the parameters it has encountered till that point and starts working with the new absolute path. Since the "malicious" parameter represents an absolute path, the result of `os.path.join` ignores the static directory completely. Hence, untrusted input is passed via the `os.path.join` call to `flask.send_file` can lead to path traversal attacks. A patch with a fix is available on the `master` branch of the GitHub repository. This can also be fixed by preventing flow of untrusted data to the vulnerable `send_file` function. In case the application logic necessiates this behaviour, one can either use the `flask.safe_join` to join untrusted paths or replace `flask.send_file` calls with `flask.send_from_directory` calls.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28452 β€Ό

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

πŸ“– Read

via "National Vulnerability Database".