πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-26729 β€Ό

Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40690 β€Ό

Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26728 β€Ό

Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43677 β€Ό

In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44467 β€Ό

A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrarily terminate active sessions of other users, causing a Denial-of-Service (DoS) condition. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

πŸ“– Read

via "National Vulnerability Database".
⚠ Serious Security: You can’t beat the house at Blackjack – or can you? ⚠

What if you could guess the next card correctly twice as often as you should?

πŸ“– Read

via "Naked Security".
πŸ•΄ Ransomware Barrage Aimed at US Healthcare Sector, Feds Warn πŸ•΄

A CISA advisory warns that the Daixin Team ransomware group has put the US healthcare system in its crosshairs for data extortion, and provides tools to fight back.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Atlassian Vulnerabilities Highlight Criticality of Cloud Services πŸ•΄

Two flaws in the popular developer cloud platform show how weaknesses in authorization functions and SaaS flaws can put cloud apps at risk.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Stress Is Driving Cybersecurity Professionals to Rethink Roles πŸ•΄

Burnout has led one-third of cybersecurity staffers to consider changing jobs over the next two years, potentially further deepening the talent shortage, research shows.

πŸ“– Read

via "Dark Reading".
πŸ•΄ IoT Fingerprinting Helps Authenticate and Secure All Those Devices πŸ•΄

For organizations struggling to protect a rapidly expanding volume of IoT devices, IoT fingerprinting could help with security and management.

πŸ“– Read

via "Dark Reading".
⚠ Serious Security: You can’t beat the house at Blackjack – or can you? ⚠

What if you could guess the next card correctly twice as often as you should?

πŸ“– Read

via "Naked Security".
⚠ Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now! ⚠

Ventura hits the market with 112 patches, Catalina's gone missing, and iPhones and iPads get a critical kernel-level zero-day patch...

πŸ“– Read

via "Naked Security".
πŸ‘3
πŸ•΄ AwareIDβ„’ Offers Lightning-Fast Identity Verification, Multi-Factor Authentication and Multi-Modal Biometrics in a Single Low-Code platform πŸ•΄

.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ PayPal Introduces More Secure Payments with Passkeys πŸ•΄

Passkeys are designed to replace passwords and allow seamless logins for consumers across devices and platforms.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Illusive's Identity Threat Detection and Response (ITDR) Solution Protects Privileged Accounts πŸ•΄

New release extends best-in-class coverage of identity vulnerability discovery and remediation.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Palo Alto Networks NextWave Program Provides the Threat Response Community With XDR for Incident Response Fueled by MSSP Demand πŸ•΄

Driving better security outcomes for customers through partner-delivered incident response services built on Cortex XDR.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Spyderbat Announces Open Source Program for Cloud Native Visibility and Security πŸ•΄

Open source tools by Spyderbat address the needs of Platform Engineering and DevOps teams by delivering new insights to workload activities and behaviors.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Akamai Announces Next Generation DDoS Defense Platform πŸ•΄

Upgrade boosts Akamai's dedicated mitigation capacity by 100% and enhances attack fighting capabilities for increasingly sophisticated DDoS threats.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Financial Services Firms Operating Under False Sense of Security πŸ•΄

Trend Micro research finds most are over-confident about ability to withstand ransomware.

πŸ“– Read

via "Dark Reading".
πŸ•΄ US Employees Feel Little Concern for Data Theft at Work, New Research Reveals πŸ•΄

.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Duality Launches First Ever Enterprise-Ready Privacy-Enhanced Data Collaboration Platform πŸ•΄

Platform delivers unmatched performance, broad analysis capabilities, and governance across any data, geo, or cloud.

πŸ“– Read

via "Dark Reading".