πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-38234 β€Ό

XPDF commit ffaf11c was discovered to contain a segmentation violation via Lexer::getObj(Object*) at /xpdf/Lexer.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38231 β€Ό

XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35434 β€Ό

jpeg-quantsmooth before commit 8879454 contained a floating point exception (FPE) via /jpeg-quantsmooth/jpegqs+0x4f5d6c.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Rolls Out Tamper Protection for Macs πŸ•΄

The tamper protection feature detects attempts to modify files and processes for Microsoft Defender for Endpoints on macOS.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-25799 β€Ό

An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.5.0. An attacker could send a link that has a specially crafted URL and convince the user to click the link. When an authenticated user clicks the link, the authenticated user's browser could be redirected to a malicious site that is designed to impersonate a legitimate website. The attacker could trick the user and potentially acquire sensitive information such as the user's credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42052 β€Ό

IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2871 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Developers still struggling with security issues during code reviews, study finds πŸ—“οΈ

The road to DevSecOps isn’t always the smoothest

πŸ“– Read

via "The Daily Swig".
πŸ‘1
⚠ US offers reward β€œup to $10 million” for information about the Conti gang ⚠

Wanted - Reward Offered - Five unknown individuals (plus a man with a weird hat)

πŸ“– Read

via "Naked Security".
⚠ Chrome browser gets 11 security fixes with 1 zero-day – update now! ⚠

Don't delay - patch today.

πŸ“– Read

via "Naked Security".
πŸ‘1
πŸ•΄ 7 Smart Ways to Secure Your E-Commerce Site πŸ•΄

Especially if your e-commerce and CMS platforms are integrated, you risk multiple potential sources of intrusion, and the integration points themselves may be vulnerable to attack.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-37459 β€Ό

Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-45454 β€Ό

Ampere Altra before SRP 1.08b and Altra Max? before SRP 2.05 allow information disclosure of power telemetry via HWmon.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Swiss Post relaunches e-voting bug bounty program πŸ—“οΈ

Ethical hackers invited to stress test election infrastructure

πŸ“– Read

via "The Daily Swig".
πŸ•΄ ThreatX Raises $30 Million in Series B Funding to Accelerate Growth in Global API Protection Market πŸ•΄

Funds will support product development and market expansion for ThreatX, which delivers real-time protection for APIs and Web apps against complex botnets, DDoS, and multimode attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ AuditBoard Launches Third-Party Risk Management Solution, Empowering Enterprises to Tackle IT Vendor Risk at Scale πŸ•΄

Solution streamlines the assessment, monitoring, and remediation of third-party risk for information security, compliance, and risk teams.

πŸ“– Read

via "Dark Reading".
❌ APT Lazarus Targets Engineers with macOS Malware ❌

The North Korean APT is using a fake job posting for Coinbase in a cyberespionage campaign targeting users of both Apple and Intel-based systems.

πŸ“– Read

via "Threat Post".
πŸ•΄ Thoma Bravo Closes $6.9B Acquisition of Identity-Security Vendor SailPoint πŸ•΄

All-cash transaction deal that was first announced in April means SailPoint is no longer a publicly traded company.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-38149 β€Ό

HashiCorp Consul Template through 0.29.1 inserts Sensitive Information into a Log File.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36186 β€Ό

A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2845 β€Ό

Buffer Over-read in GitHub repository vim/vim prior to 9.0.0217.

πŸ“– Read

via "National Vulnerability Database".
πŸ€”1