πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Tanium Partners With ScreenMeet to Enable Employees to Securely Connect to Their Remote Desktops πŸ•΄

partnership lets users access one-click ScreenMeet sessions from the Tanium platform.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zscaler Adds New AI/ML Capabilities for the Zscaler Zero Trust Exchange πŸ•΄

Organizations can strengthen their network defense with a number of intelligent security innovations.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zscaler and AWS Expand Relationship πŸ•΄

Zscaler also announced innovations built on Zscaler’s Zero Trust architecture and AWS.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zscaler Launches Posture Control Solution πŸ•΄

Enables DevOps and security teams to prioritize and remediate risks in cloud-native applications earlier in the development life cycle.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-32549 β€Ό

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20651 β€Ό

A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this issue to be exploited. This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system. A successful exploit could allow the attacker to view the credentials of other users of the shared device.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ One in every 13 incidents blamed on API insecurity – report πŸ—“οΈ

Larger organizations are statistically more at risk, warns Imperva

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Getting a Better Handle on Identity Management in the Cloud πŸ•΄

Treat identity management as a first-priority problem, not something to figure out later while you get your business up and running in the cloud.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23080 β€Ό

In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Fresh Magecart Skimmer Attack Infrastructure Flagged by Analysts πŸ•΄

Don't sleep on Magecart attacks, which security teams could miss by relying solely on automated crawlers and sandboxes, experts warn.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Russia's APT28 Launches Nuke-Themed Follina Exploit Campaign πŸ•΄

Researchers have spotted the threat group, also known as Fancy Bear and Sofacy, using the Windows MSDT vulnerability to distribute information stealers to users in Ukraine.

πŸ“– Read

via "Dark Reading".
πŸ” Suit Claims Ex-Consultant Stole 30,000 Files to Start Competing Firm πŸ”

A new lawsuit alleges this consultant stole a library of data from his former employer - copying it from cloud storage to a USB drive - to start a competing firm.

πŸ“– Read

via "".
πŸ•΄ Aqua Security Collaborates With Center for Internet Security to Create Guide for Software Supply Chain Security πŸ•΄

In addition, Aqua Security unveiled a new open source tool, Chain-Bench, for auditing the software supply chain to ensure compliance with the new CIS guidelines.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Neustar Security Services Launches Public UltraDNS Health Check Site πŸ•΄

Open service generates free report detailing potential gaps in compliance, configuration, and security for a user’s multiple domain names.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-23081 β€Ό

In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32159 β€Ό

In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Synopsys Completes Acquisition of WhiteHat Security πŸ•΄

Addition of WhiteHat Security provides Synopsys with SaaS capabilities and dynamic application security testing (DAST) technology.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft 365 Users in US Face Raging Spate of Attacks πŸ•΄

A voicemail-themed phishing campaign is hitting specific industry verticals across the country, bent on scavenging credentials that can be used for a range of nefarious purposes.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 80% of Legacy MSSP Users Planning MDR Upgrade πŸ•΄

False positives and staff shortages are inspiring a massive managed detection and response (MDR) services migration, research finds.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2017-20085 β€Ό

A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-20090 β€Ό

A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.

πŸ“– Read

via "National Vulnerability Database".