πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ How to Upskill Tech Staff to Meet Cybersecurity Needs πŸ•΄

Cybersecurity is the largest current tech skills gap; closing it requires a concerted effort to upskill existing staff.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, heathcare security [Audio + Text] ⚠

Latest episode - listen now (or read if you prefer!)

πŸ“– Read

via "Naked Security".
πŸ•΄ Summertime Blues: TA558 Ramps Up Attacks on Hospitality, Travel Sectors πŸ•΄

The cybercriminal crew has used 15 malware families to target travel and hospitality companies globally, constantly changing tactics over the course of its four-year history.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Which Security Bugs Will Be Exploited? Researchers Create an ML Model to Find Out πŸ•΄

How critical is that vulnerability? University researchers are improving predictions of which software flaws will end up with an exploit, a boon for prioritizing patches and estimating risk.

πŸ“– Read

via "Dark Reading".
❌ Google Patches Chrome’s Fifth Zero-Day of the Year ❌

Google has patched the fifth actively exploited zero-day vulnerability discovered in Chrome this year as one in a series of fixes included in a stable channel update released Wednesday. The bug, tracked as CVE-2022-2856 and rated as high on the Common Vulnerability Scoring System (CVSS), is associated with β€œinsufficient validation of untrusted input in Intents,” […]

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Vulnerability in open source identity management system Free IPA could lead to XXE attacks πŸ—“οΈ

Attackers could β€˜take full control of the infrastructure’, warn researchers

πŸ“– Read

via "The Daily Swig".
β™ŸοΈ PayPal Phishing Scam Uses Invoices Sent Via PayPal β™ŸοΈ

Scammers are using invoices sent through PayPal.com to trick recipients into calling a number to dispute a pending charge. The missives -- which come from Paypal.com and include a link at Paypal.com that displays an invoice for the supposed transaction -- state that the user's account is about to be charged hundreds of dollars. Recipients who call the supplied toll-free number to contest the transaction are soon asked to download software that lets the scammers assume remote control over their computer.

πŸ“– Read

via "Krebs on Security".
⚠ Apple patches double zero-day in browser and kernel – update now! ⚠

Double 0-day exploits - one in WebKit (to break in) and the other in the kernel (to take over). Patch now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-36024 β€Ό

A fork of discord.py py-cord is a modern, easy to use, feature-rich, and async ready API wrapper for Discord written in Python. This issue allows users to be able to remotely shutdown the a bot running on py-cord, via adding it to a discord server with the `application.commands` scope but not the `bot` scope - then executing a command in that server. Currently, it appears that all public bots that use slash commands are affected. This issue has been patched in version 2.0.1. There are currently no recommended workarounds - please upgrade to a patched version.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 5 Russia-Linked Groups Target Ukraine in Cyberwar πŸ•΄

Information on the attributed cyberattacks conducted since the beginning of the Russia-Ukraine war shows that a handful of groups conducted more than two dozen attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-37060 β€Ό

FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the contents of files located outside of the server's restricted path.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Mac Attack: North Korea's Lazarus APT Targets Apple's M1 Chip πŸ•΄

Lazarus continues to expand an aggressive, ongoing spy campaign, using fake Coinbase job openings to lure in victims.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-36023 β€Ό

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the gateway client. There are no known workarounds, users must upgrade to version 2.4.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2874 β€Ό

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0223.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ China's APT41 Embraces Baffling Approach for Dropping Cobalt Strike Payload πŸ•΄

The state-sponsored threat actor has switched up its tactics, also adding an automated SQL-injection tool to its bag of tricks for initial access.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2020-27787 β€Ό

A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35174 (starterkit) β€Ό

A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37061 (flir_ax8_firmware) β€Ό

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2625 β€Ό

A vulnerability found in postgresql. On this security issue an attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL blocks this attack in the core server, so there's no need to modify individual extensions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32862 β€Ό

The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27790 β€Ό

A floating point exception issue was discovered in UPX in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. The highest impact is to Availability.

πŸ“– Read

via "National Vulnerability Database".