πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-31239 β€Ό

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this sensitive data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26870 β€Ό

Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34438 β€Ό

Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5355 β€Ό

The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39272 β€Ό

Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change FluxΓƒΒ’Γ’β€šΒ¬Γ’β€žΒ’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or `.spec.timeout` (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields `.spec.interval` and `.spec.timeout`, however upgrading to the latest versions is still the recommended mitigation.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ Embracing the Next Generation of Business Developers πŸ•΄

Security teams that embrace low-code/no-code can change the security mindset of business users.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Nok Nok, a Global Leader in Customer Passwordless Authentication, Releases Full Support for Passkeys πŸ•΄

Nok Nok, an inventor of FIDO authentication standards, announces full support for passkeys in its S3 Authentication Suite that allows organizations to replace passwords.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Scribe Security Launches Evidence-Based Security Trust Hub πŸ•΄

Security, DevSecOps, and DevOps teams can now build transparent trust in the software they deliver or use.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybersecurity's Role in Combating Midterm Election Disinformation πŸ•΄

A multilayered attack technique that took center stage in 2020 and has only grown more endemic.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Hornetsecurity Launches Next-Generation Security Awareness Training to Help Organizations Strengthen Their Human Firewall πŸ•΄

Best-in-class awareness training comes after a marked increase in cybersecurity risks and attacks in 2022.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ HyperSQL DataBase flaw leaves library vulnerable to RCE πŸ—“οΈ

Mishandling of untrusted input issue resolved by developers

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Uptycs Introduces Detections that Correlate Threat Activity from the Kubernetes Control Plane and Container Runtime πŸ•΄

Comprehensive CNAPP coverage for Kubernetes and containers in a single solution.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Godspeed Capital-Backed SilverEdge Partners with Counter Threat Solutions πŸ•΄

Affiliation adds new all-source and counterintelligence, cyber, software development, and identity intelligence capabilities to SilverEdge's growing suite of technology solutions focused on the US intelligence community.

πŸ“– Read

via "Dark Reading".
πŸ“’ Best free malware removal tools 2022 πŸ“’

Worried your device is infected? Here are some of the best free tools for removing malicious software from your systems

πŸ“– Read

via "ITPro".
πŸ“’ Cynet unveils new global partner programme πŸ“’

XDR platform provider strengthens its channel-first business model to help boost partners sales

πŸ“– Read

via "ITPro".
πŸ“’ NCSC founder details 'biggest regret' in underestimating organised cyber crime πŸ“’

In a rare public address, Martin also detailed his proudest achievement and how the idea for the NCSC came to be

πŸ“– Read

via "ITPro".
πŸ“’ Pendragon's zealous response to LockBit ransomware is a breath of fresh air πŸ“’

In a sea of peers that do the bare minimum, the Nottinghamshire-based car dealership is flying the flag for responsible incident disclosure

πŸ“– Read

via "ITPro".
πŸ“’ The sooner the FIDO Alliance can shut down passwords, the better πŸ“’

Passwords aren’t going anywhere, but that hasn’t stopped the dream of a passwordless future – and it seems that Apple, Google and Microsoft agree

πŸ“– Read

via "ITPro".
πŸ“’ UK outsourcer Interserve fined Β£4.4 million for litany of data protection failings πŸ“’

The numerous security blunders allowed cyber attackers to comprise its systems, install malware, and access the personal data of 113,000 of its staff

πŸ“– Read

via "ITPro".
πŸ“’ The future of work is already here. Now’s the time to secure it. πŸ“’

Robust security to protect and enable your business

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ Australia to increase maximum data breach penalty to $50 million πŸ“’

The country's government is looking to raise the maximum fine from $2 million AUD and introduce new legislation to handle cyber attacks better

πŸ“– Read

via "ITPro".