πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ 1.1 million Tesla cars recalled over software glitch πŸ“’

The mass recall is prompted by a flaw in the vehicles' automatic window reversal system

πŸ“– Read

via "ITPro".
πŸ“’ Fancy Bear hackers exploit PowerPoint files to spread Graphite malware πŸ“’

The ongoing attack reportedly targets entities in the defense and government sectors of the European Union and Eastern European nations

πŸ“– Read

via "ITPro".
πŸ“’ TikTok considers changes to data policies amid rising security concerns πŸ“’

The ByteDance-owned app also faces a potential Β£27m fine over privacy violations

πŸ“– Read

via "ITPro".
πŸ“’ Mozilla patches high-severity security flaws in new β€˜speedy’ Firefox release πŸ“’

Numerous vulnerabilities across Mozilla's products could potentially lead to code execution and system takeover

πŸ“– Read

via "ITPro".
πŸ“’ Cloudflare unveils first zero trust SIM for mobile devices πŸ“’

New wireless carrier program will also let carriers integrate Zero Trust security into existing corporate plans

πŸ“– Read

via "ITPro".
πŸ“’ GitHub alerts users to active phishing campaign πŸ“’

The attack revolves around counterfeit CircleCI notifications urging users to accept updated terms of use and privacy policy

πŸ“– Read

via "ITPro".
πŸ“’ 35 cyber startups join largest UK government-backed accelerator πŸ“’

The startups will benefit from business masterclasses, mentoring and engineering support, and technical product development support

πŸ“– Read

via "ITPro".
πŸ“’ GoTo Resolve Basic review: An SMB-friendly remote support service πŸ“’

This good-value hosted remote support service is ideal for SMBs that demand zero-trust access security

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-32168 β€Ό

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3333 β€Ό

A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.2.5 is able to address this issue. It is recommended to upgrade the affected component. VDB-209370 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3332 β€Ό

A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System. This affects an unknown part of the file router.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-209583.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3348 β€Ό

Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim.

πŸ“– Read

via "National Vulnerability Database".
⚠ WhatsApp β€œzero-day exploit” news scare – what you need to know ⚠

Is WhatsApp currently under active attack by cyercriminals? Is this a clear and current danger? How worried should WhatsApp users be?

πŸ“– Read

via "Naked Security".
πŸ•΄ Jamf Announces Intent to Acquire ZecOps, to Provide a Market-Leading Security Solution for Mobile Devices as Targeted Attacks Continue to Grow πŸ•΄

ZecOps extends Jamf's mobile security capabilities by adding advanced detections and incident response.

πŸ“– Read

via "Dark Reading".
⚠ Optus breach – Aussie telco told it will have to pay to replace IDs ⚠

Licence compromised? Passport number burned? Need a new one? Who's going to pay?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-40486 β€Ό

TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3349 β€Ό

A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2760 β€Ό

In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Rancher stored secrets in plaintext, exposed Kubernetes clusters to takeover πŸ—“οΈ

Maintainers patch vulnerability and offer mitigation advice over bug that affects all Kubernetes objects

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Illumio Introduces New Solution to Stop Endpoint Ransomware from Spreading Across the Hybrid Attack Surface πŸ•΄

Illumio Endpoint extends zero trust segmentation to see risk and set policy across macOS and Windows devices.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Vulnerability in Apache Pulsar allowed manipulator-in-the-middle attacks πŸ—“οΈ

Clients vulnerable due to improper certificate validation

πŸ“– Read

via "The Daily Swig".