πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Open source packages with millions of installs hacked to harvest AWS credentials πŸ“’

Two popular open source packages used by Python and PHP developers have been quietly compromised with successful attacks already being reported

πŸ“– Read

via "ITPro".
πŸ“’ DOE β€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œfundsβ€Œ β€Œdevelopment of Qunnect's Quantum Repeater πŸ“’

The $1.85 million grant will eventually pave the way for quantum internet

πŸ“– Read

via "ITPro".
❌ Cybergang Claims REvil is Back, Executes DDoS Attacks ❌

Actors claiming to be the defunct ransomware group are targeting one of Akami’s customers with a Layer 7 attack, demanding an extortion payment in Bitcoin.

πŸ“– Read

via "Threat Post".
⚠ Poisoned Python and PHP packages purloin passwords for AWS access ⚠

More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-42692 β€Ό

There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Most Common Threats in DBIR πŸ•΄

Supply chain and ransomware attacks increased dramatically this year, which explains why so many data breaches in this year's DBIR were grouped as system intrusion.

πŸ“– Read

via "Dark Reading".
⚠ Who’s watching your webcam? The Screencastify Chrome extension story… ⚠

When you really need to make exceptions in cybersecurity, specify them as explicitly as you can.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-29720 β€Ό

74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40317 β€Ό

Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42859 β€Ό

A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29721 β€Ό

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42860 β€Ό

A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Canadian healthcare provider issues data breach warning after server hack πŸ—“οΈ

SHN plays down concerns over medical records breach

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Big Cyber Hits on GM, Chicago Public Schools, & Zola Showcase the Password Problem πŸ•΄

Credential-stuffing attacks against online accounts are still popular, and they work thanks to continuing password reuse.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Act Now: Leveraging PCI Compliance to Improve Security πŸ•΄

Let the threat landscape guide your company's timeline for complying with new data security standards for credit cards. Use the phase-in time to improve security overall β€” security as a process β€” not just comply with new standards.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Quanta Servers Caught With Pantsdown BMC Vulnerability πŸ•΄

Researchers discover 3-year-old critical firmware vulnerability running in popular cloud servers used to power hyperscalers and cloud providers alike.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ LinkedIn bug bounty program goes public with rewards of up to $18k πŸ—“οΈ

Social media platform ends private program after paying $250,000 in rewards over eight years

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-29687 β€Ό

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4231 β€Ό

A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication first. Upgrading to version 11.0.5 and 11.1.0-next.3 is able to address this issue. The name of the patch is ba8da742e3b243e8f43d4c63aa842b44e14f2b09. It is recommended to upgrade the affected component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29680 β€Ό

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29670 β€Ό

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del.

πŸ“– Read

via "National Vulnerability Database".