πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now! ⚠

Ventura hits the market with 112 patches, Catalina's gone missing, and iPhones and iPads get a critical kernel-level zero-day patch...

πŸ“– Read

via "Naked Security".
⚠ Clearview AI image-scraping face recognition service hit with €20m fine in France ⚠

"We told you to stop but you ignored us," said the French regulator, "so now we're coming after you again."

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-43750 β€Ό

drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43747 β€Ό

baramundi Management Agent (bMA) in baramundi Management Suite (bMS) 2021 R1 and R2 and 2022 R1 allows remote code execution. This is fixed in 2022 R2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31256 β€Ό

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25849 β€Ό

The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Dark Reading Launches New Section Dedicated to ICS/OT Security πŸ•΄

ICS/OT Security joins the lineup of 14 cybersecurity topic sections on the media site.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Top 10 Kubernetes Security Risks Every DevSecOps Pro Should Know πŸ•΄

The mission to run any containerized application on any infrastructure makes security a challenge on Kubernetes.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Baltimore/Washington International Thurgood Marshall Airport Selects Telos to Process Background Checks for Aviation Workers πŸ•΄

Telos' aviation channeling service offers increased efficiency and flexibility in credentialing operations at the busiest airport in the Washington-Baltimore region.

πŸ“– Read

via "Dark Reading".
πŸ›  nfstream 6.5.3 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Rezilion Vulnerability Scanner Benchmark Report Finds Top Scanners Only 73% Accurate πŸ•΄

Majority of vulnerability scanner tools overwhelming teams with false positives and missing exploitable vulnerabilities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Open Source Is Just the Tip of the Iceberg in Software Supply Chain Security πŸ•΄

As more of the software stack consists of third-party code, it's time for a more-advanced open source vetting system.

πŸ“– Read

via "Dark Reading".
πŸ•΄ BlackBerry Launches Cyber Threat Intelligence Service to Strengthen Cyber Defenses πŸ•΄

New service from BlackBerry's Threat Research and Intelligence Team reduces unknowns to enhance detection and response.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Valence Security Announces $25M Series A to Scale Delivery of Collaborative SaaS Security Remediation Solutions to Customers πŸ•΄

Led by Microsoft's M12 venture fund, Valence's Series A round accelerates the company's ability to help customers secure their SaaS mesh from risk created by democratized end-user adoption, third-party integrations, unmanaged identities, and external data sharing.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google Enters Into Stipulated Agreement to Improve Legal Process Compliance Program πŸ•΄

Google admitted to loss of data responsive to 2016 search warrant and agreed to program enhancements, reporting obligations, and a first-of-its-kind Independent Compliance Professional.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 54% of Staff Would Reconsider Working for a Firm That Had Experienced a Cyber Breach, Research Finds πŸ•΄

Independent research from Encore uncovers hidden costs of cyber attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Content Security Market Worth $2.2 Million by 2027 - Exclusive Study by MarketsandMarkets(TM) πŸ•΄

Concerns about breaches of sensitive information due to execution of malware scripts and growing adoption of cloud-based services are fueling growth of the content security market.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cisco Warns AnyConnect VPNs Under Active Cyberattack πŸ•΄

Older bugs in the AnyConnect Secure Mobility Client are being targeted in the wild, showcasing patch-management failures.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 4 Reasons Open Source Matters for Cloud Security πŸ•΄

When we depend on an open commons as our computing foundation, we need it to be secure, and the most effective way to do that is through open solutions.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Jira Align flaws enabled malicious users to gain super admin privileges – and potentially worse πŸ—“οΈ

Lateral or upwards movement beyond the instance was theoretically possible, concludes researcher

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-39357 β€Ό

Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.

πŸ“– Read

via "National Vulnerability Database".