πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-2344 β€Ό

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-1837 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-5598 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Reverses Course on Blocking Office Macros by Default πŸ•΄

Security experts criticize company for reversing course on a decision it made just this February to block macros in files downloaded from the Internet.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Reverses Course on Blocking Office Macros by Default πŸ•΄

Security experts criticize company for reversing course, albeit temporarily, on a decision it made just this February to block macros in files downloaded from the Internet.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-35412 β€Ό

Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the product) to disable some of the agent functionality and then exfiltrate files to an external USB device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31137 β€Ό

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2353 β€Ό

Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ NCSC and ICO chiefs plead with lawyers to stop making ransomware payments πŸ“’

The two UK authorities say misconceptions around ICO fines are jeopardising the integrity of UK cyber security, in a direct appeal to the Law Society

πŸ“– Read

via "ITPro".
πŸ“’ Web3 projects lose over $2 billion to hacks and exploits in 2022 πŸ“’

Blockchain and crypto schemes have already lost more in the first half of this year than throughout all of 2021

πŸ“– Read

via "ITPro".
πŸ“’ Russia-linked state-sponsored hackers launch fresh attacks by abusing latest red team tool πŸ“’

Researchers said the new tool has evaded the detection of many leading security products and is quickly growing in popularity

πŸ“– Read

via "ITPro".
❀1
πŸ“’ SHI malware attack causes major disruption and forces staff offline πŸ“’

IT supplier says there's no evidence to suggest customer data was exfiltrated during the "security incident" attack

πŸ“– Read

via "ITPro".
πŸ“’ Marriott hit by data breach through social engineering πŸ“’

Unknown attackers were reportedly able to exfiltrate 20GB of information from the company

πŸ“– Read

via "ITPro".
πŸ“’ Experts bemoan Microsoft’s 'terrible' backtrack on blocking VBA macros πŸ“’

Experts express bewilderment over the decision to reverse the long-overdue macro block, as fears mount that cyber criminals can take advantage

πŸ“– Read

via "ITPro".
πŸ“’ Southwest Health Center hit by data breach πŸ“’

So far, there have been no reports of foul play or misuse of exposed data

πŸ“– Read

via "ITPro".
πŸ“’ Online Safety Bill: Messaging apps 'forced to scan messages' for child abuse content in fresh amendment πŸ“’

Apps utilising end-to-end encryption would require backdoors or new mechanisms to allow user data to be scanned and passed on to authorities

πŸ“– Read

via "ITPro".
πŸ“’ Kaspersky appoints new territory manager for UK&I πŸ“’

Channel veteran Stuart Peters is tasked with expanding the cybersecurity provider’s presence in the region

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ The new wave of cyber security threats facing critical national infrastructure (CNI) πŸ“’

CNI is increasingly becoming a viable target, thanks to a litany of new malware strains, with cyber attacks threatening to have serious consequences

πŸ“– Read

via "ITPro".
πŸ“’ QR codes are just as insecure as anything else πŸ“’

A browser locked down tighter than a duck’s derriere won’t save you from phishing attacks – but getting to grips with the latest advice and best practice might

πŸ“– Read

via "ITPro".
πŸ“’ UK government must 'engage with tech giants' on foreign policy πŸ“’

The Foreign Affairs Committee urge the government to work more closely with big tech, which is becoming the new battleground for threats to national privacy and security

πŸ“– Read

via "ITPro".
πŸ“’ Apple launching Lockdown Mode with iOS 16 πŸ“’

Apple breaks its bug bounty record with $2 million top prize, alongside $10 million grant funding, as it launches industry-first protections for highly targeted individuals

πŸ“– Read

via "ITPro".