πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ TLStorm 2.0: Millions of Aruba and Avaya network switches affected by RCE flaws πŸ—“οΈ

Patches issued for vulnerabilities arising from misuse of NanoSSL TLS library

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Aryaka, Carnegie Mellon’s CyLab to Research New Threat Mitigation Techniques πŸ•΄

The security research partnership will focus on developing new techniques and releasing them as open source.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1571 β€Ό

Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ...

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42192 β€Ό

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ State Bar of Georgia reels from cyber-attack πŸ—“οΈ

Bar suspends website after mystery assault

πŸ“– Read

via "The Daily Swig".
❌ Attackers Use Event Logs to Hide Fileless Malware ❌

A sophisticated campaign utilizes a novel anti-detection method.

πŸ“– Read

via "Threat Post".
πŸ›  Clam AntiVirus Toolkit 0.105.0 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ SAC Health System Impacted By Security Incident πŸ•΄

Six boxes of paper documents were removed from the facility without authorization in early March.

πŸ“– Read

via "Dark Reading".
πŸ•΄ AutoRABIT Secures $26M in Series B Investment from Full In Partners to Expand DevSecOps Platform πŸ•΄

AutoRABIT intends to direct the funding toward growth initiatives and product development.

πŸ“– Read

via "Dark Reading".
πŸ•΄ What Stars Wars Teaches Us About Threats πŸ•΄

The venerable film franchise shows us how to take threats in STRIDE.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Uptycs Announces New Cloud Identity and Entitlement Management (CIEM) Capabilities πŸ•΄

Also adds support for Google Cloud Platform (GCP) and Microsoft Azure, and PCI compliance coverage.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-42185 β€Ό

wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28111 β€Ό

MyBatis PageHelper v1.x.x-v5.x.x was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28096 β€Ό

Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Zero-day bug in uClibc library could leave IoT devices vulnerable to DNS poisoning attacks πŸ—“οΈ

Unpatched flaw caused by the predictability of transaction IDs

πŸ“– Read

via "The Daily Swig".
⚠ Firefox hits 100*, fixes bugs… but no new zero-days this month ⚠

Despite concerns that some websites might break when Chromium and then Firefox reached version 100, the web still seems to be intact.

πŸ“– Read

via "Naked Security".
πŸ•΄ AI for Cybersecurity Shimmers With Promise, But Challenges Abound πŸ•΄

Companies see AI-powered cybersecurity tools and systems as the future, but at present nearly 90% of them say they face significant hurdles in making use of them.

πŸ“– Read

via "Dark Reading".
⚠ Android monthly updates are out – critical bugs found in critical places! ⚠

Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-29347 β€Ό

An arbitrary file upload vulnerability in Web@archiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28552 β€Ό

Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28081 β€Ό

A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to execute arbitrary web scripts.

πŸ“– Read

via "National Vulnerability Database".