πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Palo Alto and Deloitte to deliver managed security services in the US πŸ“’

Freshly expanded strategic partnership will deliver threat protection, 5G security, and enable the Zero Trust Enterprise for US businesses

πŸ“– Read

via "ITPro".
πŸ“’ Google Russia files for bankruptcy, ends operations in the country πŸ“’

The asset seizure by Russian authorities has made it impossible for the company to pay employees or suppliers

πŸ“– Read

via "ITPro".
πŸ“’ Linux-based Cheerscrypt ransomware found targeting VMware ESXi servers πŸ“’

Cheerscrypt malware could cause severe disruption to companies using the virtualisation software

πŸ“– Read

via "ITPro".
πŸ“’ Mastering endpoint security implementation πŸ“’

More devices connecting to the corporate network means more security risks. Here are some of the ways to protect your business

πŸ“– Read

via "ITPro".
πŸ“’ Intuit issues yet another phishing warning to QuickBooks customers πŸ“’

The latest announcement marks the fifth phishing security advisory the company has made for QuickBooks users this year

πŸ“– Read

via "ITPro".
πŸ“’ Google Chrome branded the least effective browser for stopping phishing attacks πŸ“’

The world's most popular browser came dead last when compared against competitors

πŸ“– Read

via "ITPro".
πŸ“’ Booz Allen Hamilton wins NASA’s $622m CyPrESS contract πŸ“’

The IDIQ β€Œcontractβ€Œ β€Œwill strengthen NASA’s β€Œβ€Œβ€Œcyber security and privacy efforts

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ The cookie phase-out might precede an AdTech apocalypse πŸ“’

With the industry phasing out third-party cookies, what does this mean for businesses reliant on them to track and improve their campaigns?

πŸ“– Read

via "ITPro".
πŸ“’ DOE β€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œfundsβ€Œ β€Œdevelopment of Qunnect's Quantum Repeater πŸ“’

The $1.85 million grant will eventually pave the way for quantum internet

πŸ“– Read

via "ITPro".
πŸ“’ Russian hackers declare war on 10 countries after failed Eurovision DDoS attack πŸ“’

Italian police thwart cyber attacks on Eurovision's voting systems from the Russian-linked hacker group Killnet after the same group targeted public sector institutions days earlier

πŸ“– Read

via "ITPro".
πŸ“’ McAfee appoints Greg Johnson as new CEO πŸ“’

Peter Leav to step down in June as anti-virus giant continues to focus on its consumer business

πŸ“– Read

via "ITPro".
πŸ•΄ Critical OAS Bugs Open Industrial Systems to Takeover πŸ•΄

The most serious flaw gives attackers a way to remotely execute code on systems that many organizations use to move data in critical ICS environments, security vendor says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1927 β€Ό

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1928 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1566 β€Ό

The Quotes llama WordPress plugin through 0.7 does not sanitise and escape Quotes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. The attack could also be performed by tricking an admin to import a malicious CSV file

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1299 β€Ό

The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1528 β€Ό

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1562 β€Ό

The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1527 β€Ό

The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0642 β€Ό

The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1583 β€Ό

The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.

πŸ“– Read

via "National Vulnerability Database".