πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Women in Cryptology – USPS celebrates WW2 codebreakers ⚠

What did you do in the war, Mom? Oh, y'know, a bit of this and that...

πŸ“– Read

via "Naked Security".
πŸ•΄ 8 Trends Driving Cybersecurity in the Public Sector πŸ•΄

CISOs and security leaders in state and local governments are dealing with increasing threats like ransomware β€” with varying degrees of cyber maturity.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Bolster Deepens Platform with Dark Web Threat Intelligence and 24/7 Support πŸ•΄

Bolster delivers intelligence and remediation across web, social media, app stores, and Dark Web, with 24/7, live SOC support.

πŸ“– Read

via "Dark Reading".
πŸ•΄ HP Launches Sure Access Enterprise to Protect High Value Data and Systems πŸ•΄

HP enhances HP Wolf Security portfolio to stop attackers hijacking privileged access to sensitive data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-42197 β€Ό

In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42201 β€Ό

Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42200 β€Ό

Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31366 β€Ό

An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42198 β€Ό

In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42199 β€Ό

Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Datadog Launches Cloud Security Management to Provide Cloud Native Application Protection πŸ•΄

Product brings together workload and infrastructure security into a single platform to provide a unified approach to protecting cloud environments.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CyCognito Launches Next Generation of Exploit Intelligence Threat Remediation Platform πŸ•΄

External attack surface management leader unveils evolution of risk intelligence solution, including a virtual sandbox environment to safely validate steps to remediation.

πŸ“– Read

via "Dark Reading".
πŸ•΄ SynSaber Adds New Dynamic Pipeline to OT Cybersecurity Platform πŸ•΄

ICS/OT cybersecurity and asset monitoring vendor improves scalability and flexibility with new update.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Corsa Security Drives Forward with Additional $10 Million Funding πŸ•΄

Latest investment to broaden integrations with top firewall vendors.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Only 4% of Security and IT Leaders Believe All of Their Cloud Data is Sufficiently Secured πŸ•΄

New cloud data survey from the Cloud Security Alliance and BigID sheds light on the state of cloud data security in 2022.

πŸ“– Read

via "Dark Reading".
πŸ•΄ New Torii Report Finds 60% of IT Leaders Don’t Know What Apps They Have πŸ•΄

Surprisingly poor cross-team collaboration leads to mismanaged SaaS, wasted money and time.

πŸ“– Read

via "Dark Reading".
πŸ›  Falco 0.33.0 πŸ› 

Sysdig Falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Anonos Secures $50 Million in IP-Backed Financing to Deliver Data Privacy Technology with 100% Accuracy and Utility to Data-Driven Enterprises πŸ•΄

Global data privacy software innovator will use growth funding, led by GT Investment Partners and facilitated by Aon, to fuel customer success and expand global partnerships, sales, marketing, and industry education.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Microsoft Office Online Server open to SSRF-to-RCE exploit πŸ—“οΈ

Behavior functioning as intended, Microsoft reportedly says, and offers mitigation advice instead

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-42176 β€Ό

In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40084 β€Ό

OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.

πŸ“– Read

via "National Vulnerability Database".