πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Boeing 737 MAX: You can no longer escape liability due to poor code πŸ“’

Known vulnerabilities in Boeing’s flight software led to two fatal crashes, as well as a landmark decision with major ramifications for software development

πŸ“– Read

via "ITPro".
πŸ“’ Second Singtel subsidiary breach in a month sees customer and client data leaked πŸ“’

The incident at Singtel subsidiary Dialog follows the earlier breach at Singtel-owned Optus, Australia's second-largest telco

πŸ“– Read

via "ITPro".
πŸ“’ Toyota discovers five-year-old email leak, customers at risk of phishing attacks πŸ“’

Security experts have said the company has no way of knowing whether the emails were accessed

πŸ“– Read

via "ITPro".
πŸ“’ GCHQ chief calls for greater quantum investment, warns of looming Chinese tech dominance πŸ“’

Jeremy Fleming said that when it comes to technology, the politically motivated actions of the Chinese state are an increasingly urgent problem that must be acknowledged and addressed

πŸ“– Read

via "ITPro".
πŸ“’ Hacker steals $566 million from Binance Bridge using proof-forgery exploit πŸ“’

An exploit discovered in the exchange platform's proof verifier let the hacker take 2m BNB without raising alarm bells

πŸ“– Read

via "ITPro".
πŸ“’ Papa John's faces class-action lawsuit for alleged misuse of session tracking scripts πŸ“’

Session replay tools are used on a variety of websites for analytics purposes, but the pizza retailer faces claims it is engaged in unreasonable profiling

πŸ“– Read

via "ITPro".
πŸ“’ Intel Alder Lake chips safe from novel exploits following source code leak, experts say πŸ“’

The mystery surrounding how the code was leaked is a more interesting story, experts told IT Pro, despite others branding the incident "scary"

πŸ“– Read

via "ITPro".
πŸ“’ NCSC: Businesses are too often 'seduced' by the attractive lure of phishing tests πŸ“’

The debate around the importance of phishing tests in cyber security rages on but businesses need to be careful if they decide to embrace them, the UK's cyber authority has warned

πŸ“– Read

via "ITPro".
πŸ“’ Meta notifies around 1 million Facebook users of potential compromise through malicious apps πŸ“’

The vast majority of apps targeting iOS users appeared to be genuine apps for managing business functions such as advertising and analytics

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft's third mitigation update for Exchange Server zero-day exploit bypassed within hours πŸ“’

The string of problematic temporary fixes for β€˜ProxyNotShell’ grows longer after a 'confusing' and 'atypical' week-long vulnerability disclosure process

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-40664 β€Ό

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3458 β€Ό

A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210559.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2720 β€Ό

In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3465 β€Ό

A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of the file /index.asp. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210700.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3464 β€Ό

A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ InterVision Announces Study Identifying Ransomware as No. 1 Threat to Business Longevity πŸ•΄

InterVision releases a new website focused on the customer experience, making B2B cybersecurity purchasing decisions easier.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-37614 β€Ό

Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42715 β€Ό

A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger arbitrary JavaScript code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40871 β€Ό

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 2 Out of 3 Companies See Zero Trust Network Access as Key to Mitigate Work-From-Anywhere Risks, According to New EMA Report πŸ•΄

Report also shows that cloud-based solutions minimize complexity to enable easy adoption by small to midsize businesses.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cloud Data Breaches Are Running Rampant. What Are the Common Characteristics? πŸ•΄

Protecting against data breaches requires detailed analysis of recent attacks for remediation and prevention.

πŸ“– Read

via "Dark Reading".