πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Single largest disclosure for vulnerabilities in industrial control security reveals 56 flaws πŸ—“οΈ

Scores of security issues in industrial control systems unveiled

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why Financial Institutions Must Double Down on Open Source Investments πŸ•΄

Open source is here to stay, and it's imperative that CIOs have a mature, open source engagement strategy, across consumption, contribution, and funding as a pillar of digital transformation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-40511 β€Ό

OBDA systemsÒ€ℒ Mastro 1.0 is vulnerable to XML Entity Expansion (aka Ò€œbillion laughsҀ�) attack allowing denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36761 β€Ό

The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40510 β€Ό

XML eXternal Entity (XXE) in OBDA systemsÒ€ℒ Mastro 1.0 allows remote attackers to read system files via custom DTDs.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39006 β€Ό

IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 213549.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Gartner: Regulation, Human Costs Will Create Stormy Cybersecurity Weather Ahead πŸ•΄

Experts tell teams to prepare for more regulation, platform consolidation, management scrutiny, and attackers with the ability to claim human casualties.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-31095 β€Ό

discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel they do not have access to can view that message using the chat message lookup endpoint, primarily affecting direct message channels. There are no known workarounds for this issue, and users are advised to update the plugin.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ RIG Exploit Kit Replaces Raccoon Stealer Trojan With Dridex πŸ•΄

After the Raccoon Stealer Trojan disappeared, the RIG Exploit Kit seamlessly adopted Dridex for credential theft.

πŸ“– Read

via "Dark Reading".
πŸ•΄ China-Linked ToddyCat APT Pioneers Novel Spyware πŸ•΄

ToddyCat's Samurai and Ninja tools are designed to give attackers persistent and deep access on compromised networks, security vendor says.

πŸ“– Read

via "Dark Reading".
πŸ•΄ VPNs Persist Despite Zero-Trust Fervor πŸ•΄

Most organizations still rely on virtual private networks for secure remote access.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 7 Ways to Avoid Worst-Case Cyber Scenarios πŸ•΄

In the wake of devastating attacks, here are some of the best techniques and policies a company can implement to protect its data.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Linux Foundation Announces Open Programmable Infrastructure Project to Drive Open Standards for New Class of Cloud Native Infrastructure πŸ•΄

Data Processing and Infrastructure Processing Units – DPU and IPU – are changing the way enterprises deploy and manage compute resources across their networks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-21952 β€Ό

An Uncontrolled Resource Consumption vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31248 β€Ό

A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46-1. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37-1.

πŸ“– Read

via "National Vulnerability Database".
❌ Discovery of 56 OT Device Flaws Blamed on Lackluster Security Culture ❌

Culture of β€˜insecure-by-design’ security is cited in discovery of bug-riddled operational technology devices.

πŸ“– Read

via "Threat Post".
❌ Elusive ToddyCat APT Targets Microsoft Exchange Servers ❌

The threat actor targets institutions and companies in Europe and Asia.

πŸ“– Read

via "Threat Post".
β™ŸοΈ Meet the Administrators of the RSOCKS Proxy Botnet β™ŸοΈ

Authorities in the United States, Germany, the Netherlands and the U.K. last week said they dismantled the "RSOCKS" botnet, a collection of millions of hacked devices that were sold as "proxies" to cybercriminals looking for ways to route their malicious traffic through someone else's computer. While the coordinated action did not name the Russian hackers allegedly behind RSOCKS, KrebsOnSecurity has identified its owner as a Russian man living abroad who also runs the world's top Russian spamming forum.

πŸ“– Read

via "Krebs on Security".
❌ Gamification of Ethical Hacking and Hacking Esports ❌

Joseph Carson, Chief Security Scientist and Advisory CISO at Delinea, explores why gamified platforms and hacking esports are the future.

πŸ“– Read

via "Threat Post".
πŸ•΄ GitHub's MFA Plans Should Spur Rest of Industry to Raise the Bar πŸ•΄

We as industry leaders should be building on what individual platforms like GitHub are doing in two critical ways: demanding third parties improve security and creating more interoperable architectures.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 80% of Firms Suffered Identity-Related Breaches in Last 12 Months πŸ•΄

With almost every business experiencing growth in human and machine identities, firms have made securing those identities a priority.

πŸ“– Read

via "Dark Reading".