πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Aunalytics Launches Security Patching Platform as a Service πŸ•΄

Expedited software patching and updating recognized as one of the most important processes to protect against system compromise from cyberattacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cyera Survey Finds One in Three Respondents Want to Minimize Cloud Data Risk πŸ•΄

Multiple providers say 'cloud data sprawl' makes managing cloud data risk a priority initiative within the next 12 months.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Israel Cybersecurity Enterprise (ICE) Teams with CybeReady to Deliver World-Class Security Training πŸ•΄

Security service provider selects cybersecurity training platform to safeguard enterprises in LATAM.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Safous Adds Browser Isolation to Its Zero-Trust Network Access Service πŸ•΄

This new function offers secure access to corporate applications and external SaaS through a virtual browser.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-2529 β€Ό

sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packets causing the process to consume large amounts of memory resulting in a denial of service.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep102: How to avoid a data breach [Audio + Transcript] ⚠

Latest episode - listen now! Tell fact from fiction in hyped-up cybersecurity news...

πŸ“– Read

via "Naked Security".
πŸ•΄ Onyxia Raises $5M to Help Companies Proactively Manage Cybersecurity Risks Using AI πŸ•΄

Onyxia, an AI-powered cybersecurity strategy and performance platform providing a centralized way for security teams to monitor and manage cybersecurity efforts in real time, has raised $5 million in seed fundraising led by World Trade Ventures with participation by Silvertech Ventures and angel investors.

πŸ“– Read

via "Dark Reading".
⚠ URGENT! Microsoft Exchange double zero-day – β€œlike ProxyShell, only different” ⚠

Double-play 0-day in Exchange - what you need to know, and what you can do

πŸ“– Read

via "Naked Security".
πŸ”₯1
πŸ•΄ With the Software Supply Chain, You Can't Secure What You Don't Measure πŸ•΄

Reports to the National Vulnerability Database jumped in 2022, but we should pay just as much attention to the flaws that are not being reported to NVD, including those affecting the software supply chain.

πŸ“– Read

via "Dark Reading".
πŸ•΄ SolarMarker Attack Leverages Weak WordPress Sites, Fake Chrome Browser Updates πŸ•΄

The SolarMarker group is exploiting a vulnerable WordPress-run website to encourage victims to download fake Chrome browser updates, part of a new tactic in its watering-hole attacks.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Bug Bounty Radar // The latest bug bounty programs for October 2022 πŸ—“οΈ

New web targets for the discerning hacker

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-41437 β€Ό

Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-23726 β€Ό

PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3371 β€Ό

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41440 β€Ό

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41439 β€Ό

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37461 β€Ό

Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Confirms Pair of Blindsiding Exchange Zero-Days, No Patch Yet πŸ•΄

The "ProxyNotShell" security vulnerabilities can be chained for remote code execution and total takeover of corporate email platforms.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Microsoft: Two New 0-Day Flaws in Exchange Server β™ŸοΈ

Microsoft Corp. is investigating reports that attackers are exploiting two previously unknown vulnerabilities in Exchange Server, a technology many organizations rely on to send and receive email. Microsoft says it is expediting work on software patches to plug the security holes. In the meantime, it is urging a subset of Exchange customers to enable a setting that could help mitigate ongoing attacks.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Trojanized, Signed Comm100 Chat Installer Anchors Supply Chain Attack πŸ•΄

Malicious Comm100 files have been found scattered throughout North America, and across sectors including tech, healthcare, manufacturing, telecom, insurance, and others.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-40274 β€Ό

Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.

πŸ“– Read

via "National Vulnerability Database".