πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2016-3701 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2016-6315 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2016-4426 β€Ό

In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Should you take your password manager off the internet? πŸ“’

How keeping data offline in a closed loop on a self-service model can help shore up all your apps and services

πŸ“– Read

via "ITPro".
πŸ“’ European company unmasked as cyber mercenary group with ties to Russia πŸ“’

The company that's similar to NSO Group has been active since 2016 and has used different zero-days in Windows and Adobe products to infect victims with powerful, evasive spyware

πŸ“– Read

via "ITPro".
πŸ“’ Equifax eyes increased fraud prevention capabilities with Midigator acquisition πŸ“’

The deal marks Equifax’s twelfth acquisition since the beginning of 2021

πŸ“– Read

via "ITPro".
πŸ“’ ZoomInfo hires new First Chief Security Officer πŸ“’

Cybersecurity expert Tomer Gershoni will oversee the software firm’s physical, digital security and privacy efforts

πŸ“– Read

via "ITPro".
πŸ“’ What is subnetting? πŸ“’

Partitioning a single network can help relieve network congestion and increase security

πŸ“– Read

via "ITPro".
πŸ“’ Fraud detection and prevention market to hit $176 billion by 2030 πŸ“’

Payment fraud ranks highest in Acumen’s recent forecast, with identity theft growing by the day

πŸ“– Read

via "ITPro".
πŸ“’ NCSC launches startup incubator to protect against national cyber threats πŸ“’

The program is focused on the protection of highly available operational technology where there is a high risk of digital sabotage

πŸ“– Read

via "ITPro".
πŸ“’ US doubles reward for information on North Korean cybercrime syndicates πŸ“’

The news follows the recent Maui ransomware attacks targeting US public health organizations

πŸ“– Read

via "ITPro".
πŸ“’ TikTok to give researchers new API for insight, greater transparency πŸ“’

Trends identified by independent analysts could inform business decisions

πŸ“– Read

via "ITPro".
β™ŸοΈ Breach Exposes Users of Microleaves Proxy Service β™ŸοΈ

Microleaves, a ten-year-old proxy service that lets customers route their web traffic through millions of Microsoft Windows computers, exposed their entire user database and the location of tens of millions of PCs running the proxy software. Microleaves claims its proxy software is installed with user consent. But research suggests Microleaves has a lengthy history of being supplied with new proxies by affiliates incentivized to install the software any which way they can -- such as by secretly bundling it with other software.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Patch Now: Atlassian Confluence Bug Under Active Exploit πŸ•΄

Attackers almost immediately leapt on a just-disclosed bug, CVE-2022-26138, affecting Atlassian Confluence, which allows remote, unauthenticated actors unfettered access to Confluence data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-34593 β€Ό

DPTech VPN v8.1.28.0 was discovered to contain an arbitrary file read vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41556 β€Ό

sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An attacker might abuse this bug to target (for example) Cloud services that allow customization via SquirrelScripts, or distribute malware through video games that embed a Squirrel Engine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2564 β€Ό

Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34578 β€Ό

Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29360 β€Ό

The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1799 β€Ό

Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3601 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. OpenSSL does not class this issue as a security vulnerability. The trusted CA store should not contain anything that the user does not trust to issue other certificates. Notes: https://github.com/openssl/openssl/issues/5236#issuecomment-1196460611

πŸ“– Read

via "National Vulnerability Database".