πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Security BSides commits to greater conference diversity after speaker backlash πŸ“’

A surprise booking of a divisive social engineer prompted a number of cyber security experts to pull out of BSides Cleveland

πŸ“– Read

via "ITPro".
πŸ“’ Cloudflare fixes outage that knocked major web services offline πŸ“’

Online services such as Nord VPN, Shopify, and Steam were all inaccessible by users in most regions

πŸ“– Read

via "ITPro".
πŸ“’ How to react to a data breach πŸ“’

Would you know what to do if an online attacker got their hands on your data? We outline the first steps you should take following a security breach

πŸ“– Read

via "ITPro".
πŸ“’ IT Pro News in Review: UK tech raises $16bn, Microsoft acquires Miburo, largest DDoS attack mitigated πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ“’ SolarWinds details 'next generation' software development process πŸ“’

The open source approach, which will be shared with the wider community, is a direct response to the SUNBURST cyber attack in 2020

πŸ“– Read

via "ITPro".
πŸ“’ Avira Free Security review: An effective antimalware suite, but heavy on the marketing πŸ“’

It’s hard to fully appreciate Avira’s malware protection when the packaging feels so manipulative

πŸ“– Read

via "ITPro".
πŸ“’ BRATA malware has evolved to target online banking across Europe, researchers warn πŸ“’

The new variant can now access SMS, GPS, and device control to better steal financial data

πŸ“– Read

via "ITPro".
πŸ“’ Okta sets aside $1 million to support cyber security training for non-profits πŸ“’

One of the projects receiving a grant will help civil society organisations in Ukraine to strengthen their cyber security

πŸ“– Read

via "ITPro".
πŸ“’ Quantum is 'the future of AWS system security', Amazon claims πŸ“’

With third major quantum investment, AWS sets stage for next decade of network infrastructure

πŸ“– Read

via "ITPro".
πŸ“’ How secure is Gmail? πŸ“’

The practical steps you should take to secure your Gmail account, from implementing 2FA to performing regular checkups

πŸ“– Read

via "ITPro".
β€Ό CVE-2020-27509 β€Ό

Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the 'subject' field. The payload executes when the recipient logs into their mailbox.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34495 β€Ό

rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34494 β€Ό

rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-9754 β€Ό

NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33202 β€Ό

Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by using alternative paths or channels for Sensor.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-33146 β€Ό

Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1846 β€Ό

The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1573 β€Ό

The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1095 β€Ό

The Mihdan: No External Links WordPress plugin through 4.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1572 β€Ό

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0722 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.

πŸ“– Read

via "National Vulnerability Database".