๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2022-42715 โ€ผ

A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger arbitrary JavaScript code execution.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-40871 โ€ผ

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด 2 Out of 3 Companies See Zero Trust Network Access as Key to Mitigate Work-From-Anywhere Risks, According to New EMA Report ๐Ÿ•ด

Report also shows that cloud-based solutions minimize complexity to enable easy adoption by small to midsize businesses.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Cloud Data Breaches Are Running Rampant. What Are the Common Characteristics? ๐Ÿ•ด

Protecting against data breaches requires detailed analysis of recent attacks for remediation and prevention.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Vectra Advances Security AI to Deliver Attack Signal Intelligenceโ„ข, Empowering Security Teams to Investigate and Respond to Attacks in Real Time ๐Ÿ•ด

Security AI-driven Attack Signal Intelligence automates cyber threat detection, triage, and prioritization across public cloud, SaaS, identity and networks.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Beachhead Solutions Adds Windows Security Management to the BeachheadSecureยฎ Platform ๐Ÿ•ด

Included at no added cost, BeachheadSecure now provides accountwide management of Microsoft Defender AV, Firewall, and Controlled Folders for the most complete PC and device security available.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-3467 โ€ผ

A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality of the file /jsoa/hntdCustomDesktopActionContent. The manipulation of the argument inforid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-210709 was assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-33106 โ€ผ

WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  Move over Patch Tuesday โ€“ itโ€™s Ada Lovelace Day! โš 

Hacking on actual computers is one thing, but hacking purposefully on imaginary computers is, these days, something we can only imagine.

๐Ÿ“– Read

via "Naked Security".
โš  Mystery iPhone update patches against iOS 16 mail crash-attack โš 

The problem with crashy messaging apps is that *other people* get to choose if and when to send you messages...

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด E-Commerce Losses to Online Payment Fraud to Exceed $48B Globally in 2023, as Fraud Incursions Evolve ๐Ÿ•ด

Study estimates a 16% growth in e-commerce fraud losses in just 12 months.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Cyolo Receives Investment from IBM Ventures for Zero Trust Secure Access Platform ๐Ÿ•ด

The investment by IBM Ventures enables further collaboration to accelerate the adoption of modernized, identity-based connectivity for today's digital organizations.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Key Takeaways From Omdia's IGA Market Radar ๐Ÿ•ด

Identity governance administration (IGA) started life as a tool for organizations to meet a sudden surge of legal and regulatory requirements, but๏ปฟ it has grown into a key enabler of security.

๐Ÿ“– Read

via "Dark Reading".
โš  Patch Tuesday in brief โ€“ one 0-day fixed, but no patches for Exchange! โš 

There's a zero-day patch, but it's not for the zero-day you thought.

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด Airborne Drones Are Dropping Cyber-Spy Exploits in the Wild ๐Ÿ•ด

Drone-based cyberattacks to spy on corporate targets are no longer hypothetical, one incident from this summer shows.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-0030 โ€ผ

An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ” 5 Multi-factor Authentication (MFA) Best Practices for 2022 ๐Ÿ”

Not all MFA strategies are created the same, so to ensure smooth MFA implementation, be sure to stick to these five best practices.


๐Ÿ“– Read

via "".
โ€ผ CVE-2022-42081 โ€ผ

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via sched_end_time parameter.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-2249 โ€ผ

Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42086 โ€ผ

Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42077 โ€ผ

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

๐Ÿ“– Read

via "National Vulnerability Database".