πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ What getting hacked taught me about cyber empathy πŸ“’

The industry needs a little less β€˜I told you so’ when it comes to dealing with victims

πŸ“– Read

via "ITPro".
πŸ“’ CrowdStrike adds invite-only tier to new partner program πŸ“’

New β€˜Elite’ tier aims to incentivise partners with new value-added bundles, discounts, and more

πŸ“– Read

via "ITPro".
πŸ“’ Anonymous hacks Iranian government and state broadcasters πŸ“’

The hacktivists announced a targeted hacking campaign against the Iranian government, supporting the recent human rights protests in the region

πŸ“– Read

via "ITPro".
πŸ“’ US lawmakers warn Apple against using Chinese chips in next iPhone πŸ“’

Senators ask the US director of national intelligence to investigate a Chinese chipmaker’s military ties

πŸ“– Read

via "ITPro".
πŸ“’ Uber launches infosec hiring spree after attributing breach to LAPSUS$ πŸ“’

The company also hinted at the belief that LAPSUS$ was also behind the attack on Rockstar Games over the weekend in a revealing update detailing the inner workings of the attack

πŸ“– Read

via "ITPro".
πŸ“’ How to secure your hybrid workforce πŸ“’

IT teams need to rethink their approach to security under our new working models

πŸ“– Read

via "ITPro".
πŸ“’ Inside the password arms race πŸ“’

To keep your partner’s business protected, you always need to stay one step ahead

πŸ“– Read

via "ITPro".
πŸ“’ Wintermute loses $162 million in DeFi hack πŸ“’

A vulnerability in the vanity address generator Profanity led to the attack

πŸ“– Read

via "ITPro".
πŸ“’ 15-year-old vulnerability found in Python module πŸ“’

Hundreds of thousands of repositories have been found to be exposed to the vulnerability

πŸ“– Read

via "ITPro".
πŸ“’ Phishing attacks targeting US government have evolved in sophistication, Cofense reports πŸ“’

The scams are aimed at stealing federal employees' Microsoft 365 credentials

πŸ“– Read

via "ITPro".
πŸ“’ Australian telco Optus confirms cyber attack involving potential leak of sensitive customer data πŸ“’

Investigations are ongoing but early signs indicate that some customers may have had identity documents and other identifying information exposed to hackers

πŸ“– Read

via "ITPro".
⚠ Uber and Rockstar – has a LAPSUS$ linchpin just been busted (again)? ⚠

Is this the same suspect as before? Is he part of LAPSUS$? Is this the man who hacked Uber and Rockstar? And, if so, who else?

πŸ“– Read

via "Naked Security".
⚠ Morgan Stanley fined millions for selling off devices full of customer PII ⚠

Critical data on old disks always seems inaccessible if you really need it. But when you DON''T want it back, guess what happens...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-3296 β€Ό

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3297 β€Ό

Use After Free in GitHub repository vim/vim prior to 9.0.0579.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41343 β€Ό

registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41347 β€Ό

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41352 β€Ό

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavisd via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavisd automatically prefers it over cpio.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36159 β€Ό

Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36158 β€Ό

Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).

πŸ“– Read

via "National Vulnerability Database".