π΄ Contrast Security Launches Expanded Security Testing Tools for JavaScript and Popular Angular, React, and jQuery Frameworks π΄
π Read
via "Dark Reading".
New language and framework support empowers developers to analyze front-end code for vulnerabilities throughout the development lifecycle.π Read
via "Dark Reading".
Darkreading
Contrast Security Launches Expanded Security Testing Tools for JavaScript and Popular Angular, React, and jQuery Frameworks
New language and framework support empowers developers to analyze front-end code for vulnerabilities throughout the development lifecycle.
π΄ New SonicWall Survey Data Reveals 91% of Organizations Fear Ransomware Attacks in 2022 π΄
π Read
via "Dark Reading".
Amid an economic downturn, cybersecurity staffing shortages, and endless cyberattacks, financially motivated attacks are the top concern among IT professionals.π Read
via "Dark Reading".
Darkreading
New SonicWall Survey Data Reveals 91% of Organizations Fear Ransomware Attacks in 2022
Amid an economic downturn, cybersecurity staffing shortages, and endless cyberattacks, financially motivated attacks are the top concern among IT professionals.
π΄ Research Reveals Microsoft Teams Security and Backup Flaws, With Over Half of Users Sharing Business-Critical Information on the Platform π΄
π Read
via "Dark Reading".
Most backup and security vendors overlook this vital communication channel.π Read
via "Dark Reading".
Darkreading
Research Reveals Microsoft Teams Security and Backup Flaws, With Over Half of Users Sharing Business-Critical Information on theβ¦
Most backup and security vendors overlook this vital communication channel.
π΄ School Is in Session: 5 Lessons for Future Cybersecurity Pros π΄
π Read
via "Dark Reading".
Opportunities in the field continue to grow β and show no signs of slowing down.π Read
via "Dark Reading".
Darkreading
School Is in Session: 5 Lessons for Future Cybersecurity Pros
Opportunities in the field continue to grow β and show no signs of slowing down.
ποΈ The exploitability advisory: CISAβs VEX offers fresh take on tackling known vulnerabilities ποΈ
π Read
via "The Daily Swig".
βSBOM turns on flashing lights on the dashboard; VEX helps you figure out which to turn offβπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
The exploitability advisory: CISAβs VEX offers fresh take on tackling known vulnerabilities
βSBOM turns on flashing lights on the dashboard; VEX helps you figure out which to turn offβ
β S3 Ep103: Scammers in the Slammer (and other stories) [Audio + Text] β
π Read
via "Naked Security".
Latest episode - listen and learn now (or read and revise, if the written word is your thing)...π Read
via "Naked Security".
Naked Security
S3 Ep103: Scammers in the Slammer (and other stories) [Audio + Text]
Latest episode β listen and learn now (or read and revise, if the written word is your thing)β¦
π΄ Russia-Linked Cybercrime Group Hawks Combo of Malicious Services With LilithBot π΄
π Read
via "Dark Reading".
The malware-as-a-service group Eternity is selling a one-stop shop for various malware modules it's been distributing individually via a subscription model on Telegram.π Read
via "Dark Reading".
Darkreading
Russia-Linked Cybercrime Group Hawks Combo of Malicious Services With LilithBot
The malware-as-a-service group Eternity is selling a one-stop shop for various malware modules it's been distributing individually via a subscription model on Telegram.
π΄ Hackers Have It Out for Microsoft Email Defenses π΄
π Read
via "Dark Reading".
Cybercriminals are focusing more and more on crafting special email attacks that evade Microsoft Defender and Office security.π Read
via "Dark Reading".
Darkreading
Hackers Have It Out for Microsoft Email Defenses
Cybercriminals are focusing more and more on crafting special email attacks that evade Microsoft Defender and Office security.
ποΈ Dex patches authentication bug that enabled unauthorized access to client applications ποΈ
π Read
via "The Daily Swig".
With 35.6 million downloads the OAuth 2.0 protocol provider has serious downstream attack surfaceπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Dex patches authentication bug that enabled unauthorized access to client applications
With 35.6 million downloads the OAuth 2.0 protocol provider has serious downstream attack surface
π Digital Guardian Wins Data Leak Detection Solution of the Year in CyberSecurity Breakthrough Awards π
π Read
via "".
Judges looked at criteria, including innovation, performance, ease of use, functionality, value, and impact, for the award.π Read
via "".
π΄ US Consumers Are Finally Becoming More Security & Privacy Conscious π΄
π Read
via "Dark Reading".
The trend, spotted by Consumer Reports, could mean good news for organizations struggling to contain remote work challenges.π Read
via "Dark Reading".
Darkreading
US Consumers Are Finally Becoming More Security & Privacy Conscious
The trend, spotted by Consumer Reports, could mean good news for organizations struggling to contain remote work challenges.
βΌ CVE-2022-37888 βΌ
π Read
via "National Vulnerability Database".
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address these security vulnerabilities.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3002 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2637 βΌ
π Read
via "National Vulnerability Database".
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects: Hitachi Storage Plug-in for VMware vCenter 04.8.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40160 βΌ
π Read
via "National Vulnerability Database".
Those using JXPath to interpret XPath may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31008 βΌ
π Read
via "National Vulnerability Database".
RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3389 βΌ
π Read
via "National Vulnerability Database".
Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32171 βΌ
π Read
via "National Vulnerability Database".
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to access the userΓ’β¬β’s credentials.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2975 βΌ
π Read
via "National Vulnerability Database".
A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and 10.1.0.0 through 10.1.0.1. Versions prior to 8.0.0.0 are end of manufacturing support and were not evaluated.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26239 βΌ
π Read
via "National Vulnerability Database".
The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows unprivileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2783 βΌ
π Read
via "National Vulnerability Database".
In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF tokenπ Read
via "National Vulnerability Database".