๐ Friday Five 6/10 ๐
๐ Read
via "".
Read up on how Apple is getting ahead of the curve on security, how you could be targeted in a Facebook phishing scam, why a different type of cyberattack could surpass ransomware, and more all in this weekโs Friday Five!
๐ Read
via "".
โผ CVE-2021-44582 โผ
๐ Read
via "National Vulnerability Database".
A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-31788 โผ
๐ Read
via "National Vulnerability Database".
IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-44117 โผ
๐ Read
via "National Vulnerability Database".
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-32563 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase Server using X.509 client certificates, the admin credentials provided to the Admin REST API are ignored, resulting in privilege escalation for unauthenticated users. The Public REST API is not impacted by this issue. A workaround is to replace X.509 certificate based authentication with Username and Password authentication inside the bootstrap configuration.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-27502 โผ
๐ Read
via "National Vulnerability Database".
RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM.๐ Read
via "National Vulnerability Database".
๐ข IBM bolsters cyber security offerings with Randori acquisition ๐ข
๐ Read
via "ITPro".
It plans to use the companyโs attack surface management and offensive security offerings to strengthen its cloud and AI capabilities๐ Read
via "ITPro".
IT PRO
IBM bolsters cyber security offerings with Randori acquisition | IT PRO
It plans to use the companyโs attack surface management and offensive security offerings to strengthen its cloud and AI capabilities
๐ข Double extortion ransomware pushes average payments close to $1 million ๐ข
๐ Read
via "ITPro".
As the average payment approaches the landmark figure, experts reflect on times when the going rate was just $500๐ Read
via "ITPro".
IT PRO
Double extortion ransomware pushes average payments close to $1 million | IT PRO
As the average payment approaches the landmark figure, experts reflect on times when the going rate was just $500
๐ข The hybrid work maturity framework ๐ข
๐ Read
via "ITPro".
Your roadmap to trusted flexible working๐ Read
via "ITPro".
IT PRO
The hybrid work maturity framework
Your roadmap to trusted flexible working
๐ข The EUโs Apple App Store crackdown โwill fuel cyber attacksโ ๐ข
๐ Read
via "ITPro".
Organisations should be encouraged to embrace the โsecurity by Playstationโ approach as much as possible, expert says๐ Read
via "ITPro".
IT PRO
The EUโs Apple App Store crackdown โwill fuel cyber attacksโ | IT PRO
Organisations should be encouraged to embrace the โsecurity by Playstationโ approach as much as possible, expert says
๐ข Cyber security companies โmust remember who the enemies areโ ๐ข
๐ Read
via "ITPro".
Tech giants must collaborate more with the wider industry, WithSecureโs CEO urges, as he lays bare European anxieties๐ Read
via "ITPro".
IT PRO
Cyber security companies โmust remember who the enemies areโ | IT PRO
Tech giants must collaborate more with the wider industry, WithSecureโs CEO urges, as he lays bare European anxieties
๐ข Kaspersky Free review: Effective and lightweight โ everything you want from a free antivirus solution ๐ข
๐ Read
via "ITPro".
Itโll be a real shame if politics means people missing out on this top-class security tool๐ Read
via "ITPro".
IT PRO
Kaspersky Free review: Effective and lightweight โ everything you want from a free antivirus solution | IT PRO
Itโll be a real shame if politics means people missing out on this top-class security tool
๐ข Cyber criminals are spending longer inside business' networks after the initial breach ๐ข
๐ Read
via "ITPro".
Cyber attackers' dwell time is up 36% thanks to initial access brokers and repeat exploitation of Microsoft Exchange vulnerabilities, according to Sophos๐ Read
via "ITPro".
ITPro
Cyber criminals are spending longer inside business' networks after the initial breach
Cyber attackers' dwell time is up 36% thanks to initial access brokers and repeat exploitation of Microsoft Exchange vulnerabilities, according to Sophos
๐ข Kali Linux team announces free cyber security training delivered live on Twitch ๐ข
๐ Read
via "ITPro".
The brand-new initiative is aimed at reaching more aspiring certified pen-testers through twice-weekly livestreamed lessons๐ Read
via "ITPro".
IT Pro
Kali Linux creators announce free cyber security sessions delivered live on Twitch
The brand-new initiative is aimed at reaching more aspiring certified pen-testers through twice-weekly livestreamed lessons
๐ข Identity: The digital trust accelerator ๐ข
๐ Read
via "ITPro".
Building trust in governments and public sector organisations๐ Read
via "ITPro".
IT PRO
Identity: The digital trust accelerator
Building trust in governments and public sector organisations
๐ข IT Pro 20/20: Disrupting cyber security ๐ข
๐ Read
via "ITPro".
Issue 29 looks at the companies and trends aiming to shake up the industry in 2022๐ Read
via "ITPro".
IT PRO
IT Pro 20/20: Disrupting cyber security | IT PRO
Issue 29 looks at the companies and trends aiming to shake up the industry in 2022
๐ข Indiaโs new cyber rules risk driving away tech companies ๐ข
๐ Read
via "ITPro".
A tech industry body has flagged that the rules could create create an โenvironment of fearโ๐ Read
via "ITPro".
IT PRO
Indiaโs new cyber rules risk driving away tech companies | IT PRO
A tech industry body has flagged that the rules could create create an โenvironment of fearโ
๐ข Businesses at work ๐ข
๐ Read
via "ITPro".
An in-depth look into how organisations and people work today, and the apps & services they use to be productive๐ Read
via "ITPro".
IT PRO
Businesses at work
An in-depth look into how organisations and people work today, and the apps & services they use to be productive
๐ข What is metaverse security? ๐ข
๐ Read
via "ITPro".
As the metaverse evolves, businesses need to think differently about virtual security to protect their IT infrastructure, staff, and customers๐ Read
via "ITPro".
IT PRO
What is metaverse security? | IT PRO
As the metaverse evolves, businesses need to think differently about virtual security to protect their IT infrastructure, staff, and customers
๐ข How to boot Windows 11 in Safe Mode ๐ข
๐ Read
via "ITPro".
Unless youโre a complete Windows novice, youโll have come across Safe Mode before - but what exactly is it, and how do you access it in Windows 11?๐ Read
via "ITPro".
ITPro
How to boot into Windows 11 Safe Mode
Long-time Windows users will already be familiar with Windows 11 Safe Mode, but what exactly is it for and how do you boot your system into it?
๐ข State-sponsored hackers delay new Microsoft Exchange Server by four years ๐ข
๐ Read
via "ITPro".
Hafnium's devastating zero-day exploit chain in 2021 forced Microsoft to improve the security of current versions instead of releasing the new one on schedule๐ Read
via "ITPro".
ITPro
State-sponsored hackers delay new Microsoft Exchange Server by four years
Hafnium's devastating zero-day exploit chain in 2021 forced Microsoft to improve the security of current versions instead of releasing the new one on schedule