πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ U.S. Healthcare Orgs Targeted with Maui Ransomware ❌

State-sponsored actors are deploying the unique malware--which targets specific files and leaves no ransomware note--in ongoing attacks.

πŸ“– Read

via "Threat Post".
πŸ•΄ ICYMI: Critical Cisco RCE Bug, Microsoft Breaks Down Hive, SHI Cyberattack πŸ•΄

Dark Reading's digest of the other don't-miss stories of the week, including a new ransomware targeting QNAP gear, and a destructive attack against the College of the Desert that lingers on.

πŸ“– Read

via "Dark Reading".
πŸ•΄ What Do All of Those Cloud Cybersecurity Acronyms Mean? πŸ•΄

Acronyms serve as a gatekeeper β€” if you don't sling the lingo, you don't belong. So here's a quick guide to the letter salad of cloud cybersecurity.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-31290 β€Ό

A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28624 β€Ό

A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the following software updates to resolve the vulnerability. HPE FlexNetwork 5130EL_7.10.R3507P02 and HPE FlexFabric 5945_7.10.R6635.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32115 β€Ό

An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-30852 β€Ό

Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28623 β€Ό

Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL and HPE IceWall SSO version 10.0 certd library Patch 9 for HP-UX.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33011 β€Ό

Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Decentralized Identifiers: Everything you need to know about the next-gen web ID tech πŸ—“οΈ

DID promises to give web users more control over their digital identities

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Zero Trust Bolsters Our National Defense Against Rising Cyber Threats πŸ•΄

The Colonial Pipeline and JBS attacks, among others, showed us our national resilience is only as strong as public-private sector collaboration.

πŸ“– Read

via "Dark Reading".
❌ Sneaky Orbit Malware Backdoors Linux Devices ❌

The novel threat steals data and can affect all processes running on the OS, stealing information from different commands and utilities and then storing it on the affected machine.

πŸ“– Read

via "Threat Post".
πŸ” Friday Five 7/8 πŸ”

In this week’s Friday Five, read more about what Apple is doing to protect users against government-backed malware, why U.S. healthcare organizations should be on high alert, how threat actors are changing their tactics, and much more.


πŸ“– Read

via "".
πŸ•΄ Coalition Closes $250 Million in Series F Funding, Valuing the Cyber Insurance Provider at $5 Billion πŸ•΄

Funding from Allianz X, Valor Equity Partners, Kinetic Partners, and existing investors will accelerate Coalition’s vision to provide security for all.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Swimlane Secures $70M Growth Round to Fuel Global Expansion of Next Generation Low-Code Security Automation Platform πŸ•΄

.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Worldwide Enterprise Endpoint Security Industry to 2027: Focus on Antivirus, Firewall, Endpoint Device Control, and Anti-Spyware/Anti-Malware πŸ•΄

.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ AstraLocker ransomware decryptors released by Emsisoft πŸ—“οΈ

Threat actor released decryption keys after abandoning malware to focus on cryptojacking

πŸ“– Read

via "The Daily Swig".
πŸ•΄ SOAR Market Worth $2.3 Billion by 2027, According to Exclusive Report by MarketsandMarkets πŸ•΄

.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Welcome-Back-to-the-Future Shock πŸ•΄

This year's RSA Conference saw a strange mix of selling the future and the past β€” for good reason.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-34166 β€Ό

IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229430.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34160 β€Ό

IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 229330.

πŸ“– Read

via "National Vulnerability Database".