πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-23267 β€Ό

.NET and Visual Studio Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-29117, CVE-2022-29145.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ What to Patch Now: Actively Exploited Windows Zero-Day Threatens Domain Controllers πŸ•΄

Microsoft's May 2022 Patch Tuesday contains several bugs in ubiquitous software that could affect millions of machines, researchers warn.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Microsoft Patch Tuesday, May 2022 Edition β™ŸοΈ

Microsoft today released updates to fix at least 74 separate security problems in its Windows operating systems and related software. This month's patch batch includes fixes for seven "critical" flaws, as well as a zero-day vulnerability that affects all supported versions of Windows.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Novel Nerbian RAT Lurks Behind Faked COVID Safety Emails πŸ•΄

Malicious emails with macro-enabled Word documents are spreading a never-before-seen remote-access Trojan, researchers say.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-26116 β€Ό

Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ NIST refreshes software supply chain risk management guidance πŸ—“οΈ

β€˜A comprehensive tool that can take you from crawl to walk to run’

πŸ“– Read

via "The Daily Swig".
❌ Ransomware Deals Deathblow to 157-year-old College ❌

Why a private college that stayed in business for 157 years had to close after the combo of COVID-19 and ransomware proved too much.

πŸ“– Read

via "Threat Post".
❌ Actively Exploited Zero-Day Bug Patched by Microsoft ❌

Microsoft's May Patch Tuesday roundup also included critical fixes for a number of flaws found in infrastructure present in many enterprise and cloud environments.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ RuTube hack: Russian video platform denies loss of source code following cyber-attack πŸ—“οΈ

The β€˜Russian alternative to YouTube’ has been offline since Monday

πŸ“– Read

via "The Daily Swig".
❌ Novel Phishing Trick Uses Weird Links to Bypass Spam Filters ❌

A novel form of phishing takes advantage of a disparity between how browsers and email inboxes read web domains.

πŸ“– Read

via "Threat Post".
❌ Intel Memory Bug Poses Risk for Hundreds of Products ❌

Dell and HP were among the first to release patches and fixes for the bug.

πŸ“– Read

via "Threat Post".
πŸ•΄ Vanity URLs Could be Spoofed for Social Engineering Attacks πŸ•΄

Attackers could abuse the vanity subdomains of popular cloud services such as Box.com, Google, and Zoom to mask attacks in phishing campaigns.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Danger of Online Data Brokers πŸ•΄

Enterprises should consider online data brokers as part of their risk exposure analysis if they don't already do so.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cyber-Espionage Attack Drops Post-Exploit Malware Framework on Microsoft Exchange Servers πŸ•΄

IceApple's 18 separate modules include those for data exfiltration, credential harvesting, and file and directory deletion, CrowdStrike warns.

πŸ“– Read

via "Dark Reading".
⚠ Colonial Pipeline facing $1,000,000 fine for poor recovery plans ⚠

How good is your cybersecurity? Are you making the same mistakes as lots of other people? Here's some real-life advice...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-29316 β€Ό

Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29727 β€Ό

Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3254 β€Ό

Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29728 β€Ό

Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29318 β€Ό

An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29655 β€Ό

An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".