πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-33675 β€Ό

Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30181, CVE-2022-33641, CVE-2022-33642, CVE-2022-33643, CVE-2022-33650, CVE-2022-33651, CVE-2022-33652, CVE-2022-33653, CVE-2022-33654, CVE-2022-33655, CVE-2022-33656, CVE-2022-33657, CVE-2022-33658, CVE-2022-33659, CVE-2022-33660, CVE-2022-33661, CVE-2022-33662, CVE-2022-33663, CVE-2022-33664, CVE-2022-33665, CVE-2022-33666, CVE-2022-33667, CVE-2022-33668, CVE-2022-33669, CVE-2022-33671, CVE-2022-33672, CVE-2022-33673, CVE-2022-33674, CVE-2022-33677.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22711 β€Ό

Windows BitLocker Information Disclosure Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35628 β€Ό

A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22022 β€Ό

Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22041, CVE-2022-30206, CVE-2022-30226.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22036 β€Ό

Performance Counters for Windows Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Microsoft Patch Tuesday, July 2022 Edition β™ŸοΈ

Microsoft today released updates to fix at least 86 security vulnerabilities in its Windows operating systems and other software, including a weakness in all supported versions of Windows that Microsoft warns is actively being exploited. The software giant also has made a controversial decision to put the brakes on a plan to block macros in Office documents downloaded from the Internet.

πŸ“– Read

via "Krebs on Security".
❌ Large-Scale Phishing Campaign Bypasses MFA ❌

Attackers used adversary-in-the-middle attacks to steal passwords, hijack sign-in sessions and skip authentication and then use victim mailboxes to launch BEC attacks against other targets.

πŸ“– Read

via "Threat Post".
πŸ•΄ QuickBooks Vishing Scam Targets Small Businesses πŸ•΄

Businesses receive an invoice via email with a credit card charge and are asked to call a fake number and hand over personal information to receive a refund.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Vivaldi browser founder Jon von Tetzchner puts privacy at the center of development πŸ—“οΈ

A man for all four seasons

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Exostar Empowers SMBs with Enhanced, Low-Cost, Easy-to-Use Microsoft 365 and CMMC 2.0 Solutions πŸ•΄

Upgrades to the Exostar platform promote secure, compliant collaboration and handling of controlled unclassified information.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Keep Humans in the Loop in SOC Operations πŸ•΄

Machine learning and automation can help free up security pros for higher-value tasks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-35257 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-10800 β€Ό

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27294 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Vulnerability in AWS IAM Authenticator for Kubernetes could allow user impersonation, privilege escalation attacks πŸ—“οΈ

Flaw in Amazon’s Kubernetes service has since been fixed

πŸ“– Read

via "The Daily Swig".
πŸ•΄ New Research Reveals 93% of Organizations Surveyed Have Had Failed IIoT/OT Security Projects πŸ•΄

Barracuda research finds organizations are struggling to protect operational technology and getting breached as a result.

πŸ“– Read

via "Dark Reading".
πŸ•΄ US Government and QuSecure Orchestrate First-Ever Post-Quantum Encryption Communication over a Government Network πŸ•΄

QuSecure’s QuProtect leverages unique post-quantum cryptographic algorithm on government legacy systems to achieve world’s first and only post-quantum resilient channel within a government facility.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft: 10,000 Orgs Targeted in Phishing Attack That Bypasses Multifactor Authentication πŸ•΄

The massive phishing campaign does not exploit a vulnerability in MFA. Instead, it spoofs an Office 365 authentication page to steal credentials.

πŸ“– Read

via "Dark Reading".
⚠ Paying ransomware crooks won’t reduce your legal risk, warns regulator ⚠

"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?

πŸ“– Read

via "Naked Security".
πŸ•΄ Survey: Small Cybersecurity Teams Face Greater Risk from Attacks than Larger Enterprises πŸ•΄

Cynet CISO survey reveals lack of staff, skills, and resources driving smaller teams to outsource security with advanced tools, technologies, and services.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-35259 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".