πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Fraud detection and prevention market to hit $176 billion by 2030 πŸ“’

Payment fraud ranks highest in Acumen’s recent forecast, with identity theft growing by the day

πŸ“– Read

via "ITPro".
πŸ“’ NCSC launches startup incubator to protect against national cyber threats πŸ“’

The program is focused on the protection of highly available operational technology where there is a high risk of digital sabotage

πŸ“– Read

via "ITPro".
πŸ“’ US doubles reward for information on North Korean cybercrime syndicates πŸ“’

The news follows the recent Maui ransomware attacks targeting US public health organizations

πŸ“– Read

via "ITPro".
πŸ“’ TikTok to give researchers new API for insight, greater transparency πŸ“’

Trends identified by independent analysts could inform business decisions

πŸ“– Read

via "ITPro".
β™ŸοΈ Breach Exposes Users of Microleaves Proxy Service β™ŸοΈ

Microleaves, a ten-year-old proxy service that lets customers route their web traffic through millions of Microsoft Windows computers, exposed their entire user database and the location of tens of millions of PCs running the proxy software. Microleaves claims its proxy software is installed with user consent. But research suggests Microleaves has a lengthy history of being supplied with new proxies by affiliates incentivized to install the software any which way they can -- such as by secretly bundling it with other software.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Patch Now: Atlassian Confluence Bug Under Active Exploit πŸ•΄

Attackers almost immediately leapt on a just-disclosed bug, CVE-2022-26138, affecting Atlassian Confluence, which allows remote, unauthenticated actors unfettered access to Confluence data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-34593 β€Ό

DPTech VPN v8.1.28.0 was discovered to contain an arbitrary file read vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41556 β€Ό

sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An attacker might abuse this bug to target (for example) Cloud services that allow customization via SquirrelScripts, or distribute malware through video games that embed a Squirrel Engine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2564 β€Ό

Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34578 β€Ό

Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29360 β€Ό

The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1799 β€Ό

Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3601 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. OpenSSL does not class this issue as a security vulnerability. The trusted CA store should not contain anything that the user does not trust to issue other certificates. Notes: https://github.com/openssl/openssl/issues/5236#issuecomment-1196460611

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24912 β€Ό

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep93: Office security, breach costs, and leisurely patches [Audio + Text] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-1277 β€Ό

Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 3 Tips for Creating a Security Culture πŸ•΄

Trying to get the whole organization on board with better cybersecurity is much tougher than it may sound.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacks πŸ—“οΈ

Reflected XSS and DOM-based XSS bugs net researchers $3,000 and $5,000 bug bounties

πŸ“– Read

via "The Daily Swig".
πŸ›  Faraday 4.0.4 πŸ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

πŸ“– Read

via "Packet Storm Security".
❌ Malicious Npm Packages Tapped Again to Target Discord Users ❌

Recent LofyLife campaign steals tokens and infects client files to monitor various user actions, such as log-ins, password changes and payment methods.

πŸ“– Read

via "Threat Post".
πŸ•΄ Malicious npm Packages Scarf Up Discord Tokens, Credit Card Info πŸ•΄

The campaign uses four malicious packages to spread "Volt Stealer" and "Lofy Stealer" malware in the open source npm software package repository.

πŸ“– Read

via "Dark Reading".