πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Novel Nerbian RAT Lurks Behind Faked COVID Safety Emails πŸ•΄

Malicious emails with macro-enabled Word documents are spreading a never-before-seen remote-access Trojan, researchers say.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-26116 β€Ό

Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ NIST refreshes software supply chain risk management guidance πŸ—“οΈ

β€˜A comprehensive tool that can take you from crawl to walk to run’

πŸ“– Read

via "The Daily Swig".
❌ Ransomware Deals Deathblow to 157-year-old College ❌

Why a private college that stayed in business for 157 years had to close after the combo of COVID-19 and ransomware proved too much.

πŸ“– Read

via "Threat Post".
❌ Actively Exploited Zero-Day Bug Patched by Microsoft ❌

Microsoft's May Patch Tuesday roundup also included critical fixes for a number of flaws found in infrastructure present in many enterprise and cloud environments.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ RuTube hack: Russian video platform denies loss of source code following cyber-attack πŸ—“οΈ

The β€˜Russian alternative to YouTube’ has been offline since Monday

πŸ“– Read

via "The Daily Swig".
❌ Novel Phishing Trick Uses Weird Links to Bypass Spam Filters ❌

A novel form of phishing takes advantage of a disparity between how browsers and email inboxes read web domains.

πŸ“– Read

via "Threat Post".
❌ Intel Memory Bug Poses Risk for Hundreds of Products ❌

Dell and HP were among the first to release patches and fixes for the bug.

πŸ“– Read

via "Threat Post".
πŸ•΄ Vanity URLs Could be Spoofed for Social Engineering Attacks πŸ•΄

Attackers could abuse the vanity subdomains of popular cloud services such as Box.com, Google, and Zoom to mask attacks in phishing campaigns.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Danger of Online Data Brokers πŸ•΄

Enterprises should consider online data brokers as part of their risk exposure analysis if they don't already do so.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cyber-Espionage Attack Drops Post-Exploit Malware Framework on Microsoft Exchange Servers πŸ•΄

IceApple's 18 separate modules include those for data exfiltration, credential harvesting, and file and directory deletion, CrowdStrike warns.

πŸ“– Read

via "Dark Reading".
⚠ Colonial Pipeline facing $1,000,000 fine for poor recovery plans ⚠

How good is your cybersecurity? Are you making the same mistakes as lots of other people? Here's some real-life advice...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-29316 β€Ό

Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29727 β€Ό

Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3254 β€Ό

Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29728 β€Ό

Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29318 β€Ό

An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29655 β€Ό

An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29656 β€Ό

Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29975 β€Ό

An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19228 β€Ό

An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

πŸ“– Read

via "National Vulnerability Database".