πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ GitHub's MFA Plans Should Spur Rest of Industry to Raise the Bar πŸ•΄

We as industry leaders should be building on what individual platforms like GitHub are doing in two critical ways: demanding third parties improve security and creating more interoperable architectures.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 80% of Firms Suffered Identity-Related Breaches in Last 12 Months πŸ•΄

With almost every business experiencing growth in human and machine identities, firms have made securing those identities a priority.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Severe Parse Server bug impacts Apple Game Center πŸ—“οΈ

Fake certificates could be used to bypass authentication controls

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-23077 β€Ό

In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23079 β€Ό

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23078 β€Ό

In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2174 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Risk of Multichannel Phishing Is on the Horizon πŸ•΄

The cybersecurity community is buzzing with concerns of multichannel phishing attacks, particularly on smishing and business text compromise, as hackers turn to mobile to launch attacks.

πŸ“– Read

via "Dark Reading".
⚠ Capital One identity theft hacker finally gets convicted ⚠

It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!

πŸ“– Read

via "Naked Security".
πŸ•΄ Evolving Beyond the Password: Vanquishing the Password πŸ•΄

Using WebAuthn, physical keys, and biometrics, organizations can adopt more advanced passwordless MFA and true passwordless systems. (Part 2 of 2)

πŸ“– Read

via "Dark Reading".
πŸ•΄ Tanium Partners With ScreenMeet to Enable Employees to Securely Connect to Their Remote Desktops πŸ•΄

partnership lets users access one-click ScreenMeet sessions from the Tanium platform.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zscaler Adds New AI/ML Capabilities for the Zscaler Zero Trust Exchange πŸ•΄

Organizations can strengthen their network defense with a number of intelligent security innovations.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zscaler and AWS Expand Relationship πŸ•΄

Zscaler also announced innovations built on Zscaler’s Zero Trust architecture and AWS.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zscaler Launches Posture Control Solution πŸ•΄

Enables DevOps and security teams to prioritize and remediate risks in cloud-native applications earlier in the development life cycle.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-32549 β€Ό

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20651 β€Ό

A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this issue to be exploited. This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system. A successful exploit could allow the attacker to view the credentials of other users of the shared device.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ One in every 13 incidents blamed on API insecurity – report πŸ—“οΈ

Larger organizations are statistically more at risk, warns Imperva

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Getting a Better Handle on Identity Management in the Cloud πŸ•΄

Treat identity management as a first-priority problem, not something to figure out later while you get your business up and running in the cloud.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23080 β€Ό

In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Fresh Magecart Skimmer Attack Infrastructure Flagged by Analysts πŸ•΄

Don't sleep on Magecart attacks, which security teams could miss by relying solely on automated crawlers and sandboxes, experts warn.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Russia's APT28 Launches Nuke-Themed Follina Exploit Campaign πŸ•΄

Researchers have spotted the threat group, also known as Fancy Bear and Sofacy, using the Windows MSDT vulnerability to distribute information stealers to users in Ukraine.

πŸ“– Read

via "Dark Reading".