βΌ CVE-2021-35487 βΌ
π Read
via "National Vulnerability Database".
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and database version information, and potentially database data.π Read
via "National Vulnerability Database".
π΄ Spring Cleaning Checklist for Keeping Your Devices Safe at Work π΄
π Read
via "Dark Reading".
Implement zero-trust policies for greater control, use BYOD management tools, and take proactive steps such as keeping apps current and training staff to keep sensitive company data safe and employees' devices secure.π Read
via "Dark Reading".
Dark Reading
Spring Cleaning Checklist for Keeping Your Devices Safe at Work
Implement zero-trust policies for greater control, use BYOD management tools, and take proactive steps such as keeping apps current and training staff to keep sensitive company data safe and employees' devices secure.
π΄ CLOP Ransomware Activity Spiked in April π΄
π Read
via "Dark Reading".
In just one month, the ransomware group's activity rose by 2,100%, a new report finds.π Read
via "Dark Reading".
Dark Reading
CLOP Ransomware Activity Spiked in April
In just one month, the ransomware group's activity rose by 2,100%, a new report finds.
π΄ Brexit Leak Site Linked to Russian Hackers π΄
π Read
via "Dark Reading".
Purporting to publish leaked emails of pro-Brexit leadership in the UK, a new site's operations have been traced to Russian cyber-threat actors, Google says.π Read
via "Dark Reading".
Dark Reading
Brexit Leak Site Linked to Russian Hackers
Purporting to publish leaked emails of pro-Brexit leadership in the UK, a new site's operations have been traced to Russian cyber-threat actors, Google says.
π΄ Meet the 10 Finalists in the RSA Conference Innovation Sandbox π΄
π Read
via "Dark Reading".
This year's finalists tackle such vital security concerns as permissions management, software supply chain vulnerability, and data governance. Winners will be announced June 6.π Read
via "Dark Reading".
Dark Reading
Meet the 10 Finalists in the RSA Conference Innovation Sandbox
This year's finalists tackle such vital security concerns as permissions management, software supply chain vulnerability, and data governance. Winners will be announced June 6.
π΄ Corelight Announces New SaaS Platform for Threat Hunting π΄
π Read
via "Dark Reading".
Corelight Investigator aids threat hunting and investigation through intelligent alert aggregation, built-in queries and scalable searchπ Read
via "Dark Reading".
Dark Reading
Corelight Announces New SaaS Platform for Threat Hunting
Corelight Investigator aids threat hunting and investigation through intelligent alert aggregation, built-in queries and scalable search
π΄ Mastercard Launches Cybersecurity βExperience Centreβ π΄
π Read
via "Dark Reading".
Experience Centre features emerging Mastercard products and solutions for securing digital payments on a global scale, including those developed locally in Vancouver.π Read
via "Dark Reading".
Dark Reading
Mastercard Launches Cybersecurity βExperience Centreβ
Experience Centre features emerging Mastercard products and solutions for securing digital payments on a global scale, including those developed locally in Vancouver.
π΄ Qualys to Unveil VMDR 2.0 at Qualys Security Conference in San Francisco π΄
π Read
via "Dark Reading".
Company will detail enhancements to Vulnerability Management, Detection and Response solution next month.π Read
via "Dark Reading".
Dark Reading
Qualys to Unveil VMDR 2.0 at Qualys Security Conference in San Francisco
Company will detail enhancements to Vulnerability Management, Detection and Response solution next month.
π΄ Cybersecurity-Focused SYN Ventures Closes $300 Million Fund II π΄
π Read
via "Dark Reading".
Cylance co-founder Ryan Permeh has joined full time as an operating partner.π Read
via "Dark Reading".
Dark Reading
Cybersecurity-Focused SYN Ventures Closes $300 Million Fund II
Cylance co-founder Ryan Permeh has joined full time as an operating partner.
π΄ Vishing Attacks Reach All Time High, According to Latest Agari and PhishLabs Report π΄
π Read
via "Dark Reading".
According to the findings, vishing attacks have overtaken business email compromise as the second most reported response-based email threat since Q3 2021.π Read
via "Dark Reading".
Dark Reading
Vishing Attacks Reach All Time High, According to Latest Agari and PhishLabs Report
According to the findings, vishing attacks have overtaken business email compromise as the second most reported response-based email threat since Q3 2021.
π΄ Zero-Click Zoom Bug Allows Code Execution Just by Sending a Message π΄
π Read
via "Dark Reading".
Google has disclosed a nasty set of six bugs affecting Zoom chat that can be chained together for MitM and RCE attacks, no user interaction required.π Read
via "Dark Reading".
Dark Reading
Zero-Click Zoom Bug Allows Code Execution Just by Sending a Message
Google has disclosed a nasty set of six bugs affecting Zoom chat that can be chained together for MitM and RCE attacks, no user interaction required.
π΄ JFrog Launches Project Pyrsia to Help Prevent Software Supply Chain Attacks π΄
π Read
via "Dark Reading".
Open source software community initiative utilizes blockchain technology.π Read
via "Dark Reading".
Dark Reading
JFrog Launches Project Pyrsia to Help Prevent Software Supply Chain Attacks
Open source software community initiative utilizes blockchain technology.
π΄ Interpol's Massive 'Operation Delilah' Nabs BEC Bigwig π΄
π Read
via "Dark Reading".
A sprawling, multiyear operation nabs a suspected SilverTerrier BEC group ringleader, exposing a massive attack infrastructure and sapping the group of a bit of its strength.π Read
via "Dark Reading".
Dark Reading
Interpol's Massive 'Operation Delilah' Nabs BEC Bigwig
A sprawling, multiyear operation nabs a suspected SilverTerrier BEC group ringleader, exposing a massive attack infrastructure and sapping the group of a bit of its strength.
βΌ CVE-2022-29402 βΌ
π Read
via "National Vulnerability Database".
TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root user without authentication.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29248 βΌ
π Read
via "National Vulnerability Database".
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middleware is disabled by default, so most library consumers will not be affected by this issue. Only those who manually add the cookie middleware to the handler stack or construct the client with ['cookies' => true] are affected. Moreover, those who do not use the same Guzzle client to call multiple domains and have disabled redirect forwarding are not affected by this vulnerability. Guzzle versions 6.5.6 and 7.4.3 contain a patch for this issue. As a workaround, turn off the cookie middleware.π Read
via "National Vulnerability Database".
π Insider Threats Responsible for 68% of UK Legal Sector Data Breaches π
π Read
via "".
Data analyzed this week highlights the percentage of data breaches carried out by insiders at law firms in the U.K.π Read
via "".
π΄ Is Your Data Security Living on the Edge? π΄
π Read
via "Dark Reading".
Gartner's security service edge fundamentally changes how companies should be delivering data protection in a cloud and mobile first world.π Read
via "Dark Reading".
Dark Reading
Is Your Data Security Living on the Edge?
Gartner's security service edge fundamentally changes how companies should be delivering data protection in a cloud and mobile first world.
π΄ Forescout Launches Forescout Frontline to Help Organizations Tackle Ransomware and Real Time Threats π΄
π Read
via "Dark Reading".
New threat hunting and risk identification service provides organizations with an enterprise-wide baseline of their threat landscape and risk exposure.π Read
via "Dark Reading".
Dark Reading
Forescout Launches Forescout Frontline to Help Organizations Tackle Ransomware and Real Time Threats
New threat hunting and risk identification service provides organizations with an enterprise-wide baseline of their threat landscape and risk exposure.
βΌ CVE-2022-29256 βΌ
π Read
via "National Vulnerability Database".
sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. If an attacker has the ability to set the value of the `PKG_CONFIG_PATH` environment variable in a build environment then they might be able to use this to inject an arbitrary command at `npm install` time. This is not part of any runtime code, does not affect Windows users at all, and is unlikely to affect anyone that already cares about the security of their build environment. This problem is fixed in version 0.30.5.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31651 βΌ
π Read
via "National Vulnerability Database".
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31650 βΌ
π Read
via "National Vulnerability Database".
In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.π Read
via "National Vulnerability Database".