๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ“ข Papa John's faces class-action lawsuit for alleged misuse of session tracking scripts ๐Ÿ“ข

Session replay tools are used on a variety of websites for analytics purposes, but the pizza retailer faces claims it is engaged in unreasonable profiling

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Intel Alder Lake chips safe from novel exploits following source code leak, experts say ๐Ÿ“ข

The mystery surrounding how the code was leaked is a more interesting story, experts told IT Pro, despite others branding the incident "scary"

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข NCSC: Businesses are too often 'seduced' by the attractive lure of phishing tests ๐Ÿ“ข

The debate around the importance of phishing tests in cyber security rages on but businesses need to be careful if they decide to embrace them, the UK's cyber authority has warned

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Meta notifies around 1 million Facebook users of potential compromise through malicious apps ๐Ÿ“ข

The vast majority of apps targeting iOS users appeared to be genuine apps for managing business functions such as advertising and analytics

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Microsoft's third mitigation update for Exchange Server zero-day exploit bypassed within hours ๐Ÿ“ข

The string of problematic temporary fixes for โ€˜ProxyNotShellโ€™ grows longer after a 'confusing' and 'atypical' week-long vulnerability disclosure process

๐Ÿ“– Read

via "ITPro".
โ€ผ CVE-2022-40664 โ€ผ

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3458 โ€ผ

A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210559.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-2720 โ€ผ

In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3465 โ€ผ

A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of the file /index.asp. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210700.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3464 โ€ผ

A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด InterVision Announces Study Identifying Ransomware as No. 1 Threat to Business Longevity ๐Ÿ•ด

InterVision releases a new website focused on the customer experience, making B2B cybersecurity purchasing decisions easier.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-37614 โ€ผ

Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42715 โ€ผ

A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger arbitrary JavaScript code execution.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-40871 โ€ผ

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด 2 Out of 3 Companies See Zero Trust Network Access as Key to Mitigate Work-From-Anywhere Risks, According to New EMA Report ๐Ÿ•ด

Report also shows that cloud-based solutions minimize complexity to enable easy adoption by small to midsize businesses.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Cloud Data Breaches Are Running Rampant. What Are the Common Characteristics? ๐Ÿ•ด

Protecting against data breaches requires detailed analysis of recent attacks for remediation and prevention.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Vectra Advances Security AI to Deliver Attack Signal Intelligenceโ„ข, Empowering Security Teams to Investigate and Respond to Attacks in Real Time ๐Ÿ•ด

Security AI-driven Attack Signal Intelligence automates cyber threat detection, triage, and prioritization across public cloud, SaaS, identity and networks.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Beachhead Solutions Adds Windows Security Management to the BeachheadSecureยฎ Platform ๐Ÿ•ด

Included at no added cost, BeachheadSecure now provides accountwide management of Microsoft Defender AV, Firewall, and Controlled Folders for the most complete PC and device security available.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-3467 โ€ผ

A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality of the file /jsoa/hntdCustomDesktopActionContent. The manipulation of the argument inforid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-210709 was assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-33106 โ€ผ

WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  Move over Patch Tuesday โ€“ itโ€™s Ada Lovelace Day! โš 

Hacking on actual computers is one thing, but hacking purposefully on imaginary computers is, these days, something we can only imagine.

๐Ÿ“– Read

via "Naked Security".