πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-41382 β€Ό

The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41387 β€Ό

The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41383 β€Ό

The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41381 β€Ό

The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42717 β€Ό

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42043 β€Ό

The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41386 β€Ό

The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41550 β€Ό

GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37617 β€Ό

Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ The best TeamViewer alternatives πŸ“’

These remote desktop software tools are feature-packed TeamViewer alternatives that can help you save money

πŸ“– Read

via "ITPro".
πŸ“’ Boeing 737 MAX: You can no longer escape liability due to poor code πŸ“’

Known vulnerabilities in Boeing’s flight software led to two fatal crashes, as well as a landmark decision with major ramifications for software development

πŸ“– Read

via "ITPro".
πŸ“’ Second Singtel subsidiary breach in a month sees customer and client data leaked πŸ“’

The incident at Singtel subsidiary Dialog follows the earlier breach at Singtel-owned Optus, Australia's second-largest telco

πŸ“– Read

via "ITPro".
πŸ“’ Toyota discovers five-year-old email leak, customers at risk of phishing attacks πŸ“’

Security experts have said the company has no way of knowing whether the emails were accessed

πŸ“– Read

via "ITPro".
πŸ“’ GCHQ chief calls for greater quantum investment, warns of looming Chinese tech dominance πŸ“’

Jeremy Fleming said that when it comes to technology, the politically motivated actions of the Chinese state are an increasingly urgent problem that must be acknowledged and addressed

πŸ“– Read

via "ITPro".
πŸ“’ Hacker steals $566 million from Binance Bridge using proof-forgery exploit πŸ“’

An exploit discovered in the exchange platform's proof verifier let the hacker take 2m BNB without raising alarm bells

πŸ“– Read

via "ITPro".
πŸ“’ Papa John's faces class-action lawsuit for alleged misuse of session tracking scripts πŸ“’

Session replay tools are used on a variety of websites for analytics purposes, but the pizza retailer faces claims it is engaged in unreasonable profiling

πŸ“– Read

via "ITPro".
πŸ“’ Intel Alder Lake chips safe from novel exploits following source code leak, experts say πŸ“’

The mystery surrounding how the code was leaked is a more interesting story, experts told IT Pro, despite others branding the incident "scary"

πŸ“– Read

via "ITPro".
πŸ“’ NCSC: Businesses are too often 'seduced' by the attractive lure of phishing tests πŸ“’

The debate around the importance of phishing tests in cyber security rages on but businesses need to be careful if they decide to embrace them, the UK's cyber authority has warned

πŸ“– Read

via "ITPro".
πŸ“’ Meta notifies around 1 million Facebook users of potential compromise through malicious apps πŸ“’

The vast majority of apps targeting iOS users appeared to be genuine apps for managing business functions such as advertising and analytics

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft's third mitigation update for Exchange Server zero-day exploit bypassed within hours πŸ“’

The string of problematic temporary fixes for β€˜ProxyNotShell’ grows longer after a 'confusing' and 'atypical' week-long vulnerability disclosure process

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-40664 β€Ό

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

πŸ“– Read

via "National Vulnerability Database".