πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Duality Launches First Ever Enterprise-Ready Privacy-Enhanced Data Collaboration Platform πŸ•΄

Platform delivers unmatched performance, broad analysis capabilities, and governance across any data, geo, or cloud.

πŸ“– Read

via "Dark Reading".
πŸ•΄ SealPath Data Classification Powered by Getvisibility Applies Artificial Intelligence to Improve Accuracy and Efficiency of Data Labelling and Protection πŸ•΄

.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Study Finds Significant Correlation Between BitSight Analytics and Cybersecurity Incidents πŸ•΄

The Marsh McLennan Cyber Risk Analytics Center conducted independent analysis of BitSight's Security Rating and risk vectors and cybersecurity incident data.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Dealers Report Dramatic Increase in Identity Fraud: Most Lack Effective Protection πŸ•΄

Identity fraud has increased at 84% of dealerships, with 60% losing three or more vehicles in the last year.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Security Leaders are Calling for Industry to Take Action and Programmatically Improve Secure Coding Education πŸ•΄

.

πŸ“– Read

via "Dark Reading".
πŸ•΄ As Vulnerabilities Soar, Slim.AI Launches 'Container Intelligence' to Give In-Depth Analysis on Hundreds of Popular Container Images πŸ•΄

Free service provides insights developers need to systematically identify and reduce container vulnerabilities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybersecurity Risks & Stats This Spooky Season πŸ•΄

From ransomware to remote workers to cyber-extortion gangs to Fred in shipping who clicks on the wrong link, cybersecurity concerns can keep you awake this season and all seasons.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Critical authentication bug in Fortinet products actively exploited in the wild πŸ—“οΈ

Chinese and Russian cyber-spies actively targeting security vulnerability

πŸ“– Read

via "The Daily Swig".
πŸ•΄ MSP Market Opportunity Report Finds Cybersecurity as Primary Growth Driver as SMBs Lack Resources to Develop Security Program In-House πŸ•΄

New report shows 75% of MSPs will invest in security threat intelligence services in the next 12 months to help businesses combat increased threats.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Melis Platform CMS patched for critical RCE flaw πŸ—“οΈ

POP chain crafted to demonstrate exploitability

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Spyderbat Raises Series A to Deliver Runtime Security Throughout Cloud Native Software Development Environments πŸ•΄

Led by NTTVC, the funding enables further development of Cloud Native Intrusion Prevention from the team that invented Network Intrusion Prevention Systems.

πŸ“– Read

via "Dark Reading".
πŸ•΄ HR Departments Play a Key Role in Cybersecurity πŸ•΄

A more secure organization starts with stronger alignment between HR and the IT operation.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Threat Groups Repurpose Banking Trojans into Backdoors πŸ•΄

Ursnif, a one-time banking Trojan also known as Gozi, becomes the latest codebase to be repurposed as a more general backdoor, as malware developers trend toward modularity.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-3393 β€Ό

The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3395 β€Ό

The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a database query, allowing users which has been given permission to run exports to execute arbitrary SQL statements, leading to a SQL Injection vulnerability. By default only users with the Administrator role can perform exports, but this can be delegated to lower privileged users as well.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35886 β€Ό

Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` and `key` HTTP parameters, as used within the `/action/wirelessConnect` handler.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32454 β€Ό

A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to remote code execution. An attacker can send a malicious XML payload to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3302 β€Ό

The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35261 β€Ό

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.The `/action/import_authorized_keys/` API is affected by command injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32775 β€Ό

An integer overflow vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to memory corruption. An attacker can make an authenticated HTTP request to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27622 β€Ό

Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".