πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Exploitation of Atlassian Confluence zero-day surges fifteen-fold in 24 hours πŸ“’

The zero-day code execution vulnerability was discovered last week and cyber attackers are already capitalising on the proof-of-concept code

πŸ“– Read

via "ITPro".
πŸ“’ Data protection policies and procedures πŸ“’

Why your company needs them, and what they should include

πŸ“– Read

via "ITPro".
πŸ—“οΈ US Justice Department offers blueprint for more β€˜innovative, secure IT capabilities’ πŸ—“οΈ

β€˜Zero trust’ architecture and secure supply chains to the fore in new strategy

πŸ“– Read

via "The Daily Swig".
πŸ•΄ A Few Simple Ways to Transform Your Cybersecurity Hiring πŸ•΄

Raytheon Intelligence & Space's Jon Check joins Dark Reading's Terry Sweeney at Dark Reading News Desk at RSA Conference to talk about how hiring must change.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep86: The crooks were in our network for HOW long?! [Podcast + Transcript] ⚠

Latest episode - listen (or read) now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-32978 β€Ό

There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Mitigating the Security Skills Shortage πŸ•΄

Panther Labs' Jack Naglieri joins Dark Reading's Terry Sweeney at Dark Reading News Desk at RSA Conference to discuss how to improve hiring and training.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Application Security Testing Is on the Mend With Automated Remediation πŸ•΄

Mend's Arabella Hallawell joins Dark Reading's Terry Sweeney at Dark Reading News Desk at RSA Conference to talk about the benefits of automated remediation.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ New Linux Malware 'Nearly Impossible to Detect' πŸ•΄

So-called Symbiote malware, first found targeting financial institutions, contains stealthy rootkit capabilities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How to Secure a High-Profile Event Like the Super Bowl πŸ•΄

Cisco's TK Keanini and the NFL's TomΓ‘s Maldonado join Dark Reading's Terry Sweeney at Dark Reading News Desk during RSA Conference to talk about end-to-end security.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How to Blunt the Virulence of the New Ransomware πŸ•΄

Halcyon's Jon Miller joins Dark Reading's Terry Sweeney at Dark Reading News Desk during RSA Conference to discuss how to mitigate ransomware.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-30611 β€Ό

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using some fields of the form in the portal UI to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 227364.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31402 β€Ό

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22479 β€Ό

IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31769 β€Ό

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system. IBM X-Force ID: 228219.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30610 β€Ό

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page. IBM X-Force ID: 227363.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29948 β€Ό

Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass attack that enables an attacker to gain access to the stored encrypted data. Normally, the encrypted disk partition with this data is unlocked by entering the correct passcode (6 to 14 digits) via the keypad and pressing the Unlock button. This authentication is performed by an unknown microcontroller. By replacing this microcontroller on a target device with one from an attacker-controlled Lepin EP-KP001 whose passcode is known, it is possible to successfully unlock the target device and read the stored data in cleartext.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22426 β€Ό

IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnerability to bypass authentication and gain unauthorized access to the Spectrum Copy Data Management catalog which contains metadata. IBM X-Force ID: 223718.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ EU Debates AI Act to Protect Human Rights, Define High-Risk Uses πŸ•΄

The commission argues that legislative action is needed to ensure a well-functioning market for AI systems that balances benefits and risks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CrowdStrike Adds Strategic Partners to CrowdXDR Alliance and Expands Falcon XDR Capabilities πŸ•΄

New CrowdXDR Alliance partners include Menlo Security, Ping Identity, and Vectra AI.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CrowdStrike Introduces Humio for Falcon, Redefining Threat Hunting with Unparalleled Scale and Speed πŸ•΄

Humio for Falcon provides long-term, cost-effective data retention with powerful index-free search and analysis of enriched security telemetry across enterprise environments

πŸ“– Read

via "Dark Reading".