πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ National security leaders fear Ukraine conflict could inform a 'blueprint' for cyber war πŸ“’

Learning from the successes and failures of the ongoing conflict could help foreign adversaries carry out more effective cyber attacks in the future, according to one national cyber security chief

πŸ“– Read

via "ITPro".
πŸ“’ Red Hat reveals new software supply chain security pattern πŸ“’

New cross-portfolio capabilities aim to help customers improve security posture and enable DevSecOps

πŸ“– Read

via "ITPro".
πŸ“’ Actively exploited Windows vulnerability reaches peak severity when paired with popular attack πŸ“’

May 2022's routine Patch Tuesday fixes seven 'critical' issues, including a familiar headache for IT administrators

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft announces new business security services led by in-house experts πŸ“’

The new services will see Microsoft's security experts providing hands-on, proactive threat hunting for businesses unable to fully build out a SOC due to the industry's skills shortage

πŸ“– Read

via "ITPro".
πŸ“’ WannaCry showed the world how not to write ransomware πŸ“’

Despite its devastating impact, cyber security researchers reflect on how much worse the attacks could have been

πŸ“– Read

via "ITPro".
πŸ“’ NCSC unveils email security-checking tool for private sector organisations at CYBERUK πŸ“’

The free service will focus on checking for TLS and DMARC compliance to protect against anti-spoofing and email hijacking

πŸ“– Read

via "ITPro".
πŸ“’ Costa Rica declares state of emergency following Conti ransomware attack πŸ“’

The US has released a $10 million bug bounty for information on the attackers

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft makes Defender for Business generally available πŸ“’

Small businesses can look forward to enterprise-grade endpoint security as well as automated investigation and remediation capabilities

πŸ“– Read

via "ITPro".
πŸ“’ GitHub to introduce two-factor authentication by 2023 πŸ“’

GitHub.com will require 2FA by the end of 2023, as the company works to secure the software ecosystem through improved account security

πŸ“– Read

via "ITPro".
πŸ“’ Researcher discovers simple tweak that neutralises Conti, REvil, WannaCry attacks πŸ“’

This one trick can stop ransomware executing file encryption

πŸ“– Read

via "ITPro".
πŸ“’ Five Eyes and US governments finally confirm Russia was behind Ukrainian government, Viasat cyber attacks πŸ“’

NCSC detailed the government-level attribution process at CYBERUK 2022 and why it took so much longer to assign blame compared to the private sector

πŸ“– Read

via "ITPro".
πŸ“’ IoT privacy and security concerns πŸ“’

We take a look at what's needed to really secure internet-connected devices

πŸ“– Read

via "ITPro".
❌ Threat Actors Use Telegram to Spread β€˜Eternity’ Malware-as-a-Service ❌

An account promoting the projectβ€”which offers a range of threat activity from info-stealing to crypto-mining to ransomware as individual modulesβ€”has more than 500 subscribers.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Ukrainian hacker jailed for selling account credentials on the dark web πŸ—“οΈ

Botnet operator had thousands of hacked credential listings, according to the DoJ

πŸ“– Read

via "The Daily Swig".
πŸ•΄ How to Avoid Falling Victim to PayOrGrief's Next Rebrand πŸ•΄

The group that shut down the second largest city in Greece was not new but a relaunch of DoppelPaymer.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Brace of Icinga web vulnerabilities β€˜easily chained’ to hack IT monitoring software πŸ—“οΈ

Open source IT monitoring system gets patched

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Data Transformation: 3 Sessions to Attend at RSA 2022 πŸ•΄

Three RSA 2022 sessions take deep dives into the security considerations around data cloud transformation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-22983 β€Ό

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30372 β€Ό

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42969 β€Ό

Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30371 β€Ό

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.

πŸ“– Read

via "National Vulnerability Database".