πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-29855 β€Ό

Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phones excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

πŸ“– Read

via "National Vulnerability Database".
❌ Novel β€˜Nerbian’ Trojan Uses Advanced Anti-Detection Tricks ❌

The stealthy, feature-rich malware has multistage evasion tactics to fly under the radar of security analysis, researchers at Proofpoint have found.

πŸ“– Read

via "Threat Post".
β™ŸοΈ DEA Investigating Breach of Law Enforcement Data Portal β™ŸοΈ

The U.S. Drug Enforcement Administration (DEA) says it is investigating reports that hackers gained unauthorized access to an agency portal that taps into 16 different federal law enforcement databases. KrebsOnSecurity has learned the alleged compromise is tied to a cybercrime and online harassment community that routinely impersonates police and government officials to harvest personal information on their targets.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ On Air With Dark Reading News Desk at Black Hat Asia 2022 πŸ•΄

This year's Black Hat Asia is hybrid, with some sessions broadcast on the virtual platform and others live on stage in Singapore. News Desk is available on-demand with prerecorded interviews.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1674 β€Ό

NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1650 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository eventsource/eventsource prior to v2.0.2.

πŸ“– Read

via "National Vulnerability Database".
❌ You Can’t Eliminate Cyberattacks, So Focus on Reducing the Blast Radius ❌

Tony Lauro, director of security technology and strategy at Akamai, discusses reducing your company's attack surface and the "blast radius" of a potential attack.

πŸ“– Read

via "Threat Post".
πŸ•΄ Nokia Opens Cybersecurity Testing Lab πŸ•΄

The end-to-end cybersecurity 5G testing lab will help identify and prevent cyberattacks on 5G networks.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Box, Zoom, Google Docs offer phishing boost with β€˜vanity URL’ flaws πŸ—“οΈ

Attack technique bypasses email filters and burnishes credibility of phishing links

πŸ“– Read

via "The Daily Swig".
πŸ•΄ 5 Years That Altered the Ransomware Landscape πŸ•΄

WannaCry continues to be a reminder of the challenges that organizations face dealing with the ransomware threat.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Known macOS Vulnerabilities Led Researcher to Root Out New Flaws πŸ•΄

Researcher shares how he unearthed newer bugs in Apple's operating system by closer scrutiny of previous research, including vulnerabilities that came out of the Pwn2Own competition.

πŸ“– Read

via "Dark Reading".
❌ Malware Builder Leverages Discord Webhooks ❌

Researchers discovered a simple malware builder designed to steal credentials, then pinging them to Discord webhooks.

πŸ“– Read

via "Threat Post".
πŸ•΄ How Can Your Business Defend Itself Against Fraud-as-a-Service? πŸ•΄

By understanding how FaaS works and following best practices to prevent it, your business can protect its customers, revenue, and brand reputation.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Researcher stops REvil ransomware in its tracks with DLL-hijacking exploit πŸ—“οΈ

Conti, Lockbit, and other prolific ransomware strains apparently have similar vulnerabilities

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-42863 β€Ό

A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28873 β€Ό

A vulnerability affecting F-Secure SAFE browser was discovered. An attacker can potentially exploit Javascript window.open functionality in SAFE Browser which could lead address bar spoofing attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28872 β€Ό

A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not correct if navigation fails in a loop.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Marcus Hutchins on halting the WannaCry ransomware attack – β€˜Still to this day it feels like it was all a weird dream’ πŸ—“οΈ

Five years since WannaCry exploded onto the scene, ransomware still tops global threat lists ANALYSIS Five years ago today (May 12), a ransomware attack by a North Korean hacking group hit computers r

πŸ“– Read

via "The Daily Swig".
⚠ Serious Security: Learning from curl’s latest bug update ⚠

Learn how to write plain-speaking and purposeful security advisories from one of the most widely-used open source tools in the world.

πŸ“– Read

via "Naked Security".
⚠ S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again) [Podcast] ⚠

Latest episode - lots to learn - plain English - fun with a serious side - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-29989 β€Ό

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking.

πŸ“– Read

via "National Vulnerability Database".