πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ UK safety tech sees another year of growth, amidst backlash πŸ“’

Record investment in the sector has led to widespread implementation of safety measures, but rights groups and some experts still aren't convinced

πŸ“– Read

via "ITPro".
πŸ“’ First Choice Community Healthcare hit by data breach πŸ“’

The Albuquerque-based firm first learned of the breach in March 2022

πŸ“– Read

via "ITPro".
πŸ“’ Tim Hortons 'offers free coffee and donut' to app users to settle data lawsuit πŸ“’

Canadian privacy commissioners found that the coffee giant had tracked and recorded the movements of its app users every few minutes of the day, even when the app wasn’t open

πŸ“– Read

via "ITPro".
πŸ“’ European energy company and gas pipeline hacked by AlphV ransomware πŸ“’

The ransomware gang responsible is also linked with the group that took down Colonial Pipeline a year ago

πŸ“– Read

via "ITPro".
πŸ“’ Nomad crypto bridge drained of $190 million through β€œchaotic” exploit πŸ“’

The Nomad team has notified law enforcement and retained leading firms for blockchain intelligence and forensics, it said in a statement on Twitter

πŸ“– Read

via "ITPro".
πŸ“’ Halborn warns of active MetaMask phishing campaign πŸ“’

The blockchain security firm deconstructs a pretentious email that attempted to steal users' passwords

πŸ“– Read

via "ITPro".
πŸ“’ Every leading UK university is compromising on email security, researchers say πŸ“’

Proofpoint said none of the top ten universities in the UK have implemented the recommended email security policies, leaving institutions open to cyber attacks

πŸ“– Read

via "ITPro".
πŸ“’ Young hacker faces 20-year prison sentence for creating prolific Imminent Monitor RAT πŸ“’

He created the RAT when he was aged just 15 and is estimated to have netted around $400,000 from the sale of it over six years

πŸ“– Read

via "ITPro".
πŸ“’ Ransomware: Sometimes you need to pay to make it go away πŸ“’

The symptoms of this distraught data victim sounded an awful lot like ransomware, and it turned out the easiest way out was the most unpalatable option

πŸ“– Read

via "ITPro".
πŸ“’ T-Mobile partners with Homeland Security to prioritize first responder data πŸ“’

Eligible T-Mobile WPS subscribers are entitled to priority service at no additional charge

πŸ“– Read

via "ITPro".
πŸ“’ Twitter API keys found leaked in over 3,200 apps, raising concerns for linked accounts πŸ“’

Business and verified Twitter accounts linked to affected apps are at risk of takeover, use in malicious campaigns

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-36197 β€Ό

BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34927 β€Ό

MilkyTracker v1.03.00 was discovered to contain a stack overflow via the component LoaderXM::load. This vulnerability is triggered when the program is supplied a crafted XM module file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27617 β€Ό

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34928 β€Ό

JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27618 β€Ό

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before 2.1.0-0390 allows remote authenticated users to delete arbitrary files via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34968 β€Ό

An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36800 β€Ό

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34943 β€Ό

Laravel v5.1 was discovered to contain a remote code execution (RCE) vulnerability via the component ChanceGenerator in __call.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27619 β€Ό

Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27616 β€Ό

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".