πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Kaspersky appoints new territory manager for UK&I πŸ“’

Channel veteran Stuart Peters is tasked with expanding the cybersecurity provider’s presence in the region

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ The new wave of cyber security threats facing critical national infrastructure (CNI) πŸ“’

CNI is increasingly becoming a viable target, thanks to a litany of new malware strains, with cyber attacks threatening to have serious consequences

πŸ“– Read

via "ITPro".
πŸ“’ QR codes are just as insecure as anything else πŸ“’

A browser locked down tighter than a duck’s derriere won’t save you from phishing attacks – but getting to grips with the latest advice and best practice might

πŸ“– Read

via "ITPro".
πŸ“’ UK government must 'engage with tech giants' on foreign policy πŸ“’

The Foreign Affairs Committee urge the government to work more closely with big tech, which is becoming the new battleground for threats to national privacy and security

πŸ“– Read

via "ITPro".
πŸ“’ Apple launching Lockdown Mode with iOS 16 πŸ“’

Apple breaks its bug bounty record with $2 million top prize, alongside $10 million grant funding, as it launches industry-first protections for highly targeted individuals

πŸ“– Read

via "ITPro".
πŸ“’ EU inches closer to blocking Meta from sending personal data to US πŸ“’

The decision still needs to be approved by other European data regulators, but could see the shut down of Instagram and Facebook on the continent

πŸ“– Read

via "ITPro".
πŸ“’ US unveils next-gen encryption tools to withstand quantum computing attacks πŸ“’

The National Institute of Standards and Technology (NIST) hopes to offer a variety of tools for quantum-proof encryption

πŸ“– Read

via "ITPro".
πŸ“’ Maui ransomware actively targeting US healthcare organizations πŸ“’

North Korean state-sponsored attackers are said to have been targeting critical services since at least May 2021

πŸ“– Read

via "ITPro".
πŸ“’ Why are ransomware gangs pivoting to Rust? πŸ“’

The developer-favourite language is fast becoming a delight for ransomware criminals

πŸ“– Read

via "ITPro".
πŸ“’ SoftBank under pressure over links with 'blacklisted' Chinese facial recognition firm πŸ“’

A subsidiary of the Japanese tech giant that conducts business with Mastercard and Visa relies on tech by the sanctioned SenseTime

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft identifies sophisticated Hive ransomware variant written in Rust πŸ“’

The move away from Go and an encryption redesign makes the new strain even more of a threat to business targets

πŸ“– Read

via "ITPro".
πŸ“’ MI5 and FBI warn businesses over mass Chinese IP theft πŸ“’

The security services urged organisations to consolidate security practices and approach Chinese business relationships with caution

πŸ“– Read

via "ITPro".
πŸ‘Ž1
β€Ό CVE-2022-27910 β€Ό

In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2365 β€Ό

stored XSS

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Experian, You Have Some Explaining to Do β™ŸοΈ

Twice in the past month KrebsOnSecurity has heard from readers who've had their accounts at big-three credit bureau Experian hacked and updated with a new email address that wasn't theirs. In both cases the readers used password managers to select strong, unique passwords for their Experian accounts. Research suggests identity thieves were able to hijack the accounts simply by signing up for new accounts at Experian using the victim's personal information and a different email address.

πŸ“– Read

via "Krebs on Security".
πŸ‘1
β€Ό CVE-2022-31571 β€Ό

The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31562 β€Ό

The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31582 β€Ό

The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31580 β€Ό

The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31578 β€Ό

The piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31579 β€Ό

The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

πŸ“– Read

via "National Vulnerability Database".