πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Rezilion Vulnerability Scanner Benchmark Report Finds Top Scanners Only 73% Accurate πŸ•΄

Majority of vulnerability scanner tools overwhelming teams with false positives and missing exploitable vulnerabilities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Open Source Is Just the Tip of the Iceberg in Software Supply Chain Security πŸ•΄

As more of the software stack consists of third-party code, it's time for a more-advanced open source vetting system.

πŸ“– Read

via "Dark Reading".
πŸ•΄ BlackBerry Launches Cyber Threat Intelligence Service to Strengthen Cyber Defenses πŸ•΄

New service from BlackBerry's Threat Research and Intelligence Team reduces unknowns to enhance detection and response.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Valence Security Announces $25M Series A to Scale Delivery of Collaborative SaaS Security Remediation Solutions to Customers πŸ•΄

Led by Microsoft's M12 venture fund, Valence's Series A round accelerates the company's ability to help customers secure their SaaS mesh from risk created by democratized end-user adoption, third-party integrations, unmanaged identities, and external data sharing.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google Enters Into Stipulated Agreement to Improve Legal Process Compliance Program πŸ•΄

Google admitted to loss of data responsive to 2016 search warrant and agreed to program enhancements, reporting obligations, and a first-of-its-kind Independent Compliance Professional.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 54% of Staff Would Reconsider Working for a Firm That Had Experienced a Cyber Breach, Research Finds πŸ•΄

Independent research from Encore uncovers hidden costs of cyber attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Content Security Market Worth $2.2 Million by 2027 - Exclusive Study by MarketsandMarkets(TM) πŸ•΄

Concerns about breaches of sensitive information due to execution of malware scripts and growing adoption of cloud-based services are fueling growth of the content security market.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cisco Warns AnyConnect VPNs Under Active Cyberattack πŸ•΄

Older bugs in the AnyConnect Secure Mobility Client are being targeted in the wild, showcasing patch-management failures.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 4 Reasons Open Source Matters for Cloud Security πŸ•΄

When we depend on an open commons as our computing foundation, we need it to be secure, and the most effective way to do that is through open solutions.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Jira Align flaws enabled malicious users to gain super admin privileges – and potentially worse πŸ—“οΈ

Lateral or upwards movement beyond the instance was theoretically possible, concludes researcher

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-39357 β€Ό

Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20954 β€Ό

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20953 β€Ό

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20933 β€Ό

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of client-supplied parameters while establishing an SSL VPN session. An attacker could exploit this vulnerability by crafting a malicious request and sending it to the affected device. A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to crash and restart, resulting in the failure of the established SSL VPN connections and forcing remote users to initiate a new VPN connection and re-authenticate. A sustained attack could prevent new SSL VPN connections from being established. Note: When the attack traffic stops, the Cisco AnyConnect VPN server recovers gracefully without requiring manual intervention. Cisco Meraki has released software updates that address this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20776 β€Ό

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20959 β€Ό

A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by persuading an authenticated administrator of the web-based management interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20955 β€Ό

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20822 β€Ό

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains certain character sequences to an affected system. A successful exploit could allow the attacker to read or delete specific files on the device that their configured administrative level should not have access to. Cisco plans to release software updates that address this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20811 β€Ό

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
⚠ Online ticketing company β€œSee” pwned for 2.5 years by attackers ⚠

Don't be a cybersecurity slowcoach - you need to spot possible attacks as soon as you can.

πŸ“– Read

via "Naked Security".
πŸ•΄ Ransomware Gangs Ramp Up Industrial Attacks in US πŸ•΄

The manufacturing segment was especially hard hit by cyberattacks in the third quarter of 2022.

πŸ“– Read

via "Dark Reading".