๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด Beachhead Solutions Adds Windows Security Management to the BeachheadSecureยฎ Platform ๐Ÿ•ด

Included at no added cost, BeachheadSecure now provides accountwide management of Microsoft Defender AV, Firewall, and Controlled Folders for the most complete PC and device security available.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-3467 โ€ผ

A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality of the file /jsoa/hntdCustomDesktopActionContent. The manipulation of the argument inforid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-210709 was assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-33106 โ€ผ

WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  Move over Patch Tuesday โ€“ itโ€™s Ada Lovelace Day! โš 

Hacking on actual computers is one thing, but hacking purposefully on imaginary computers is, these days, something we can only imagine.

๐Ÿ“– Read

via "Naked Security".
โš  Mystery iPhone update patches against iOS 16 mail crash-attack โš 

The problem with crashy messaging apps is that *other people* get to choose if and when to send you messages...

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด E-Commerce Losses to Online Payment Fraud to Exceed $48B Globally in 2023, as Fraud Incursions Evolve ๐Ÿ•ด

Study estimates a 16% growth in e-commerce fraud losses in just 12 months.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Cyolo Receives Investment from IBM Ventures for Zero Trust Secure Access Platform ๐Ÿ•ด

The investment by IBM Ventures enables further collaboration to accelerate the adoption of modernized, identity-based connectivity for today's digital organizations.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Key Takeaways From Omdia's IGA Market Radar ๐Ÿ•ด

Identity governance administration (IGA) started life as a tool for organizations to meet a sudden surge of legal and regulatory requirements, but๏ปฟ it has grown into a key enabler of security.

๐Ÿ“– Read

via "Dark Reading".
โš  Patch Tuesday in brief โ€“ one 0-day fixed, but no patches for Exchange! โš 

There's a zero-day patch, but it's not for the zero-day you thought.

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด Airborne Drones Are Dropping Cyber-Spy Exploits in the Wild ๐Ÿ•ด

Drone-based cyberattacks to spy on corporate targets are no longer hypothetical, one incident from this summer shows.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-0030 โ€ผ

An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ” 5 Multi-factor Authentication (MFA) Best Practices for 2022 ๐Ÿ”

Not all MFA strategies are created the same, so to ensure smooth MFA implementation, be sure to stick to these five best practices.


๐Ÿ“– Read

via "".
โ€ผ CVE-2022-42081 โ€ผ

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via sched_end_time parameter.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-2249 โ€ผ

Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42086 โ€ผ

Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42077 โ€ผ

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-28887 โ€ผ

Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42087 โ€ผ

Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42079 โ€ผ

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-42078 โ€ผ

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-41403 โ€ผ

OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter.

๐Ÿ“– Read

via "National Vulnerability Database".