πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-20673 β€Ό

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20666 β€Ό

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20806 β€Ό

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1897 β€Ό

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20667 β€Ό

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20669 β€Ό

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ New Chaos Malware Variant Ditches Wiper for Encryption πŸ•΄

The Chaos ransomware-builder was known for creating destructor malware that overwrote files and made them unrecoverable -- but the new Yashma version finally generates binaries that can encrypt files of all sizes.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Scammer Behind $568M International Cybercrime Syndicate Gets 4 Years πŸ•΄

The 14th defendant behind The Infraud Organization contraband marketplace has been sentenced, this time for one count of racketeering.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-27780 β€Ό

The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27781 β€Ό

The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Space Force Expands Cyber Defense Operations πŸ•΄

Space Force's Delta 6 cyber-defense group adds squadrons, updates legacy Satellite Control Network.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Exposed Kubernetes Clusters, Kubelet Ports Can Be Abused in Cyberattacks πŸ•΄

Organizations must ensure their kubelets and related APIs aren’t inadvertently exposed or lack proper access control, offering an easy access point for malicious actors.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-25878 β€Ό

The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ AVG AntiVirus Free review: Great malware protection, though the upsell is a turn-off πŸ“’

AVG serves up the same powerful antivirus engine as Avast, but the trimmings aren’t as generous

πŸ“– Read

via "ITPro".
πŸ“’ Google adds new security vendor plugins for Chrome, improved Chrome OS policy controls for IT admins πŸ“’

New integrations across various security pillars aim to improve Chrome OS and Chrome browser security for enterprise customers

πŸ“– Read

via "ITPro".
πŸ“’ Avast One Essential review: A great free antivirus solution with some tempting extra features πŸ“’

If Microsoft Defender isn’t doing it for you, Avast has you covered with strong protection in a user-friendly package

πŸ“– Read

via "ITPro".
πŸ“’ (ISC)2 launches free scheme to get 100,000 UK citizens into cyber security πŸ“’

The certification non-profit estimates the UK has around 33,000 cyber security vacancies, with that figure set to rise this year

πŸ“– Read

via "ITPro".
πŸ“’ US indicts heart doctor for allegedly spearheading high-profile ransomware operations πŸ“’

The 55-year-old cardiologist profited from a ransomware side hustle and coached would-be hackers in using his tools for maximum rewards

πŸ“– Read

via "ITPro".
πŸ“’ QuSecure launches industry-first 'quantum security as a service' πŸ“’

The post-quantum cyber security solution is targeted at enterprises and β€Œgovernment entities

πŸ“– Read

via "ITPro".
πŸ“’ Open source packages with millions of installs hacked to harvest AWS credentials πŸ“’

Two popular open source packages used by Python and PHP developers have been quietly compromised with successful attacks already being reported

πŸ“– Read

via "ITPro".