πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Transforming SQL Queries Bypasses WAF Security πŸ•΄

A team of university researchers finds a machine learning-based approach to generating HTTP requests that slip past Web application firewalls.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Black Hat Asia: Firmware Supply-Chain Woes Plague Device Security πŸ•΄

The supply chain for firmware development is vast, convoluted, and growing out of control: patching security vulnerabilities can take up to two years. For cybercriminals, it's a veritable playground.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-29218 β€Ό

RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily replaced in the CDN cache by a malicious package. The bug has been patched, and is believed to have never been exploited, based on an extensive review of logs and existing gems by rubygems. The easiest way to ensure that an application has not been exploited by this vulnerability is to verify all downloaded .gems checksums match the checksum recorded in the RubyGems.org database. RubyGems.org has been patched and is no longer vulnerable to this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27134 β€Ό

EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string memo` parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Data for 120 army recruits found on the dark web πŸ“’

The website, run jointly with Capita, has been offline since mid-March as MoD assesses the scope of the breach

πŸ“– Read

via "ITPro".
πŸ“’ Millions of Lenovo laptops thought to be vulnerable to newly discovered UEFI malware attacks πŸ“’

ESET researchers said the core vulnerabilities were 'easy' to spot due to "unfortunate" and "honest" driver names

πŸ“– Read

via "ITPro".
πŸ“’ Encryption battle plays out in Australian Parliament πŸ“’

The opposition said that the government is β€œaddicted to secrecy”

πŸ“– Read

via "ITPro".
πŸ“’ Datadog's ASM platform unmasks attack flows at code level πŸ“’

The service employs distributed tracing to identify cyber criminals

πŸ“– Read

via "ITPro".
πŸ“’ Ransomware demands in Japan are almost 26 times higher than in the UK, report finds πŸ“’

Ransom demands tend to be lower in order to make it easier for organisations to pay them, according to Sophos researchers

πŸ“– Read

via "ITPro".
πŸ“’ The truth about cyber security training πŸ“’

Stop ticking boxes. Start delivering real change.

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft's latest VPN-like feature brings added network privacy to Edge users πŸ“’

The Microsoft Edge Secure Network feature is currently available in preview and offers similar data privacy protections to Apple's Private Relay tool

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft announces lucrative new bug bounty awards for M365 products and services πŸ“’

The new awards will focus on scenario-based weaknesses and offer bonuses of up to 30% for the most severe bugs

πŸ“– Read

via "ITPro".
πŸ“’ How cyber security history repeats itself πŸ“’

The prime threats to businesses continue to be the same threats we’ve seen for the past decade – and if your business isn’t prepared, you might be at legal risk

πŸ“– Read

via "ITPro".
πŸ“’ The state of brand protection 2021 πŸ“’

A new front opens up in the war for brand safety

πŸ“– Read

via "ITPro".
πŸ“’ ConnectWise unveils new incident response service πŸ“’

New offering provides an β€œimmediate lifeline” to a team of cyber experts in the event of a security breach

πŸ“– Read

via "ITPro".
πŸ“’ Funky Pigeon site offline after "cyber incident" πŸ“’

The WH Smith-owned card site has reported the breach to "the relevant regulators"

πŸ“– Read

via "ITPro".
πŸ“’ How governments can build resilience in a new normal πŸ“’

The cloud enables the flexibility public organisations need to overcome disruption

πŸ“– Read

via "ITPro".
πŸ“’ Vector Capital acquires majority ownership of WatchGuard πŸ“’

Global private equity firm gobbles up shares from co-investors as it doubles down on its commitment to the cyber security platform provider

πŸ“– Read

via "ITPro".
πŸ“’ How do you become an ethical hacker? πŸ“’

We examine what certifications do you need, what jobs are available and how much you can expect to be paid

πŸ“– Read

via "ITPro".
πŸ“’ What is phishing? πŸ“’

From banking scams to industrial espionage, we look at why phishing is so lucrative

πŸ“– Read

via "ITPro".
πŸ“’ Almost half of UK employees can't spot email scams πŸ“’

"Jargon" and confusing terminology cited as an issue, according to OpenText survey

πŸ“– Read

via "ITPro".