πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 7 NFT Scams That Could Be Targeting Your Brand πŸ•΄

Brands should be vigilant to ensure sites and listings promoting NFTs for sale are legitimate and not being used as an instrument by fraudsters to swindle customers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Akamai Launches New Malware Protection for Uploaded Files πŸ•΄

Edge-based solution detects and blocks malicious files uploaded to Web apps and APIs.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Harnessing AI to Proactively Thwart Threats πŸ•΄

By using artificial intelligence to predict how an attacker would carry out their attack, we can deploy defenses and preemptively shut down vulnerable entry points.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1991 β€Ό

A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.php of the Master List. The manipulation of the argument Description with the input foo "><img src="" onerror="alert(document.cookie)"> leads to cross site scripting. It is possible to launch the attack remotely but it requires authentication. Exploit details have been disclosed to the public.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ KrebsOnSecurity in New Netflix Series on Cybercrime β™ŸοΈ

Netflix has a new documentary series airing next week -- "Web of Make Believe: Death, Lies & the Internet" -- in which Yours Truly apparently has a decent amount of screen time. The debut episode explores the far-too-common harassment tactic of "swatting" -- wherein fake bomb threats or hostage situations are phoned in to police as part of a scheme to trick them into visiting potentially deadly force on a target’s address.

πŸ“– Read

via "Krebs on Security".
πŸ—“οΈ Google showers top cloud security researchers with kudos and cash πŸ—“οΈ

More than $300,000 was handed out in GCP prize money during 2021

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Enterprise Security Around the Dinner Table πŸ•΄

Enterprise cybersecurity awareness training has evolved to include informal lessons for employees’ family members, and it has many benefits.

πŸ“– Read

via "Dark Reading".
⚠ Know your enemy! Learn how cybercrime adversaries get in… ⚠

Here's how 144 recent attacks actually went down in real life. Don't let this happen to you!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-31025 β€Ό

Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-passed` branches, inviting users on sites that use single sign-on could bypass the `must_approve_users` check and invites by staff are always approved automatically. The issue is patched in Discourse version 2.8.4 on the `stable` branch and version `2.9.0.beta5` on the `beta` and `tests-passed` branches. As a workaround, disable invites or increase `min_trust_level_to_allow_invite` to reduce the attack surface to more trusted users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29564 β€Ό

Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastructure, aka WND-44801.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25361 β€Ό

WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the system. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31495 β€Ό

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37589 β€Ό

Virtua Cobranca before 12R allows SQL Injection on the login page.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How the C-Suite Puts Shoulders Into Zero Trust in 2022 πŸ•΄

A full 77% of tech executives say they'll increase spending in zero-trust architecture in the coming year.

πŸ“– Read

via "Dark Reading".
πŸ•΄ RSAC Opens With Message of Transformation πŸ•΄

Cybersecurity needs to shift its thinking ahead of the next disruption, RSA's CEO said during the opening 2022 conference keynote.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-31028 β€Ό

MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due to HTTP clients not closing the connections. Public-facing MinIO deployments are most affected. Users should upgrade to RELEASE.2022-06-02T02-11-04Z to receive a patch. One possible workaround is to use a reverse proxy to limit the number of connections being attempted in front of MinIO, and actively rejecting connections from such malicious clients.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31279 β€Ό

Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution (RCE) via an unserialized pop chain in __destruct in Illuminate\Broadcasting\PendingBroadcast.php and __call in Faker\Generator.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Multilevel Extortion: DeadBolt Ransomware Targets Internet-Facing NAS Devices πŸ•΄

The innovative ransomware targets NAS devices, has a multitiered payment and extortion scheme as well as a flexible configuration, and takes a heavily automated approach.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Mandia: Keep 'Shields Up' to Survive the Current Escalation of Cyberattacks πŸ•΄

As Mandiant CEO Kevin Mandia's company prepares to become part of Google, the incident response company continues to investigate many of the most critical cyber incidents.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-36536 β€Ό

A vulnerability was found in Brandbugle. It has been rated as critical. Affected by this issue is some unknown functionality of the file /main.php. The manipulation leads to sql injection. The attack may be launched remotely.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30716 β€Ό

Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.

πŸ“– Read

via "National Vulnerability Database".