πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-33179 β€Ό

A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with Ò€œset contextҀ� and escalate privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28170 β€Ό

Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33182 β€Ό

A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands Ò€œsupportlinkҀ�, Ò€œfirmwaredownloadҀ�, Ò€œportcfgupload, license, and Ò€œfosexecҀ�.

πŸ“– Read

via "National Vulnerability Database".
⚠ Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now! ⚠

Ventura hits the market with 112 patches, Catalina's gone missing, and iPhones and iPads get a critical kernel-level zero-day patch...

πŸ“– Read

via "Naked Security".
⚠ Clearview AI image-scraping face recognition service hit with €20m fine in France ⚠

"We told you to stop but you ignored us," said the French regulator, "so now we're coming after you again."

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-43750 β€Ό

drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43747 β€Ό

baramundi Management Agent (bMA) in baramundi Management Suite (bMS) 2021 R1 and R2 and 2022 R1 allows remote code execution. This is fixed in 2022 R2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31256 β€Ό

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25849 β€Ό

The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Dark Reading Launches New Section Dedicated to ICS/OT Security πŸ•΄

ICS/OT Security joins the lineup of 14 cybersecurity topic sections on the media site.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Top 10 Kubernetes Security Risks Every DevSecOps Pro Should Know πŸ•΄

The mission to run any containerized application on any infrastructure makes security a challenge on Kubernetes.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Baltimore/Washington International Thurgood Marshall Airport Selects Telos to Process Background Checks for Aviation Workers πŸ•΄

Telos' aviation channeling service offers increased efficiency and flexibility in credentialing operations at the busiest airport in the Washington-Baltimore region.

πŸ“– Read

via "Dark Reading".
πŸ›  nfstream 6.5.3 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Rezilion Vulnerability Scanner Benchmark Report Finds Top Scanners Only 73% Accurate πŸ•΄

Majority of vulnerability scanner tools overwhelming teams with false positives and missing exploitable vulnerabilities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Open Source Is Just the Tip of the Iceberg in Software Supply Chain Security πŸ•΄

As more of the software stack consists of third-party code, it's time for a more-advanced open source vetting system.

πŸ“– Read

via "Dark Reading".
πŸ•΄ BlackBerry Launches Cyber Threat Intelligence Service to Strengthen Cyber Defenses πŸ•΄

New service from BlackBerry's Threat Research and Intelligence Team reduces unknowns to enhance detection and response.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Valence Security Announces $25M Series A to Scale Delivery of Collaborative SaaS Security Remediation Solutions to Customers πŸ•΄

Led by Microsoft's M12 venture fund, Valence's Series A round accelerates the company's ability to help customers secure their SaaS mesh from risk created by democratized end-user adoption, third-party integrations, unmanaged identities, and external data sharing.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google Enters Into Stipulated Agreement to Improve Legal Process Compliance Program πŸ•΄

Google admitted to loss of data responsive to 2016 search warrant and agreed to program enhancements, reporting obligations, and a first-of-its-kind Independent Compliance Professional.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 54% of Staff Would Reconsider Working for a Firm That Had Experienced a Cyber Breach, Research Finds πŸ•΄

Independent research from Encore uncovers hidden costs of cyber attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Content Security Market Worth $2.2 Million by 2027 - Exclusive Study by MarketsandMarkets(TM) πŸ•΄

Concerns about breaches of sensitive information due to execution of malware scripts and growing adoption of cloud-based services are fueling growth of the content security market.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cisco Warns AnyConnect VPNs Under Active Cyberattack πŸ•΄

Older bugs in the AnyConnect Secure Mobility Client are being targeted in the wild, showcasing patch-management failures.

πŸ“– Read

via "Dark Reading".