🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2022-3726

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

📖 Read

via "National Vulnerability Database".
CVE-2022-2761

An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.

📖 Read

via "National Vulnerability Database".
CVE-2022-3285

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

📖 Read

via "National Vulnerability Database".
CVE-2022-3793

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

📖 Read

via "National Vulnerability Database".
Exchange 0-days fixed (at last) – plus 4 brand new Patch Tuesday 0-days!

In all the excitement, we kind of lost track ourselves. Were there six 0-days, or only four?

📖 Read

via "Naked Security".
Emergency code execution patch from Apple – but not an 0-day

Not a zero-day, but important enough for a quick-fire patch to one system system library...

📖 Read

via "Naked Security".
🗓️ Google Pixel screen-lock hack earns researcher $70k 🗓️

Android security pwned by PUK reset trick

📖 Read

via "The Daily Swig".
🕴 Global Automotive Cybersecurity Market Report 2022: Expected Mandate for Cybersecurity Protocols to Significantly Boost Sector 🕴

As vehicle security expands to cover cyber threats on the vehicle as well as the vehicle's external network, cross-industry collaboration and market opportunities are expected to increase.

📖 Read

via "Dark Reading".
🕴 Where Are All of the Container Breaches? 🕴

Containers and their supporting infrastructure are too important to ignore.

📖 Read

via "Dark Reading".
🕴 Now That EDR Is Obvious, What Comes Next? 🕴

First in our series addressing the top 10 unanswered questions in security: What's going to replace EDR?

📖 Read

via "Dark Reading".
🕴 The Art of Calculating the Cost of Risk 🕴

Insurance and legislation affect how enterprises balance between protecting against breaches and recovering from them.

📖 Read

via "Dark Reading".
🕴 Cyber-Threat Actor Uses Booby-Trapped VPN App to Deploy Android Spyware 🕴

"SandStrike," the latest example of espionage-aimed Android malware, relies on elaborate social media efforts and back-end infrastructure.

📖 Read

via "Dark Reading".
🕴 LastPass Research Finds False Sense of Cybersecurity Running Rampant 🕴

Cybersecurity concerns and education have not mitigated the overuse of the same passwords in 2022.

📖 Read

via "Dark Reading".
🕴 Name That Edge Toon: Talk Turkey 🕴

Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

📖 Read

via "Dark Reading".
🕴 FTC Gives Chegg an 'F' for Careless Cybersecurity Impacting 40M Students 🕴

Ed-tech company Chegg is ordered by FTC to secure its systems after repeated breaches that exposed tens of millions of users' personal data.

📖 Read

via "Dark Reading".
🕴 Alethea Closes $10M Series A Financing Led by Ballistic Ventures 🕴

Investment to advance efforts to detect and mitigate disinformation.

📖 Read

via "Dark Reading".
🕴 (ISC)² Expands DEI Initiative with International Partnership Agreements 🕴

Major partnership program aims to break down barriers and empower underrepresented groups in cybersecurity across the globe.

📖 Read

via "Dark Reading".
🕴 Mimecast Unveils Email Security, Cloud Integrated for Optimized Flexibility and Speed 🕴

Award-winning email security leader expands best-in-class offerings with gateway-less deployment solution that streamlines security, increases visibility, and enhances efficacy for IT teams.

📖 Read

via "Dark Reading".
🕴 The Sky Is Not Falling: Disclosed OpenSSL Bugs Are Serious but Not Critical 🕴

Organizations should update to the latest encryption (version 3.0.7) as soon as possible, but there's no need for Heartbleed-like panic, security experts say.

📖 Read

via "Dark Reading".
🕴 PQShield and Riscure Collaborate on Post-Quantum Cryptography SCA Validation 🕴

The project will advance understanding of how quantum-secure algorithms can be secured against side channel analysis through robust validation and countermeasures.

📖 Read

via "Dark Reading".
🕴 Certificate-Based Authentication With YubiKeys for Microsoft, Third-Party, and Web Applications Now Available on iOS and Android 🕴

.

📖 Read

via "Dark Reading".