โผ CVE-2022-40750 โผ
๐ Read
via "National Vulnerability Database".
IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236588.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-36377 โผ
๐ Read
via "National Vulnerability Database".
Incorrect default permissions in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-36789 โผ
๐ Read
via "National Vulnerability Database".
Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0053 may allow a privileged user to potentially enable escalation of privilege via local access.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-38099 โผ
๐ Read
via "National Vulnerability Database".
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 may allow a privileged user to potentially enable escalation of privilege via local access.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-36938 โผ
๐ Read
via "National Vulnerability Database".
DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, potentially allowing remote code execution during processing of a 3rd party Android APK file.๐ Read
via "National Vulnerability Database".
๐1
โ Dangerous SIM-swap lockscreen bypass โ update Android now! โ
๐ Read
via "Naked Security".
A bit like leaving the front door keys under the doormat...๐ Read
via "Naked Security".
Naked Security
Dangerous SIM-swap lockscreen bypass โ update Android now!
A bit like leaving the front door keys under the doormatโฆ
๐2
๐ด Quantum Cryptography Apocalypse: A Timeline and Action Plan ๐ด
๐ Read
via "Dark Reading".
Quantum computing's a clear threat to encryption, and post-quantum crypto means adding new cryptography to hardware and software without being disruptive.๐ Read
via "Dark Reading".
Dark Reading
Quantum Cryptography Apocalypse: A Timeline and Action Plan
Quantum computing's a clear threat to encryption, and post-quantum crypto means adding new cryptography to hardware and software without being disruptive.
๐ด Avatier Achieves ISO 27001 Certification for its Information Security Management System ๐ด
๐ Read
via "Dark Reading".
Designation recognizes highest caliber of information security.๐ Read
via "Dark Reading".
Dark Reading
Avatier Achieves ISO 27001 Certification for its Information Security Management System
Designation recognizes highest caliber of information security.
๐ด Privacy4Cars Secures Fourth Patent to Remove Privacy Information From Vehicles and Create Compliance Logs ๐ด
๐ Read
via "Dark Reading".
Data-deletion service's patent covers removing personal information such as geolocation, biometrics, and phone records from a vehicle by using a user-computing device๐ Read
via "Dark Reading".
Dark Reading
Privacy4Cars Secures Fourth Patent to Remove Privacy Information From Vehicles and Create Compliance Logs
Data-deletion service's patent covers removing personal information such as geolocation, biometrics, and phone records from a vehicle by using a user-computing device
๐1
๐๏ธ All Day DevOps: Third of Log4j downloads still pull vulnerable version despite threat of supply chain attacks ๐๏ธ
๐ Read
via "The Daily Swig".
AppSec engineer keynote says Log4j revealed lessons were not learned from the Equifax breach๐ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
All Day DevOps: Third of Log4j downloads still pull vulnerable version despite threat of supply chain attacks
AppSec engineer keynote says Log4j revealed lessons were not learned from the Equifax breach
โ โGucci Masterโ business email scammer Hushpuppi gets 11 years โ
๐ Read
via "Naked Security".
Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...๐ Read
via "Naked Security".
Naked Security
โGucci Masterโ business email scammer Hushpuppi gets 11 years
Learn how to protect yourself from big-money tricksters like the Hushpuppis of the worldโฆ
๐ด Unpatched Zimbra Platforms Are Probably Compromised, CISA Says ๐ด
๐ Read
via "Dark Reading".
Attackers are targeting Zimbra systems in the public and private sectors, looking to exploit multiple vulnerabilities, CISA says.๐ Read
via "Dark Reading".
Dark Reading
Unpatched Zimbra Platforms Are Probably Compromised, CISA Says
Attackers are targeting Zimbra systems in the public and private sectors, looking to exploit multiple vulnerabilities, CISA says.
๐1
๐ด Australia Declares War on Cybercrime Syndicates ๐ด
๐ Read
via "Dark Reading".
An international counter-ransomware task force has been announced by Australian authorities following the recent Optus and Medibank data breaches.๐ Read
via "Dark Reading".
Dark Reading
Australia Declares War on Cybercrime Syndicates
An international counter-ransomware task force has been announced by Australian authorities following the recent Optus and Medibank data breaches.
๐คฏ2๐1
๐ด Researchers Sound Alarm on Dangerous BatLoader Malware Dropper ๐ด
๐ Read
via "Dark Reading".
BatLoader has spread rapidly to roost in systems globally, tailoring payloads to its victims.๐ Read
via "Dark Reading".
Dark Reading
Researchers Sound Alarm on Dangerous BatLoader Malware Dropper
BatLoader has spread rapidly to roost in systems globally, tailoring payloads to its victims.
๐1๐ค1
๐ด Evolving Security for Government Multiclouds ๐ด
๐ Read
via "Dark Reading".
As the threat landscape increases, public cloud security needs to evolve.๐ Read
via "Dark Reading".
Dark Reading
Evolving Security for Government Multiclouds
As the threat landscape increases, public cloud security needs to evolve.
๐๏ธ Mastodon users vulnerable to password-stealing attacks ๐๏ธ
๐ Read
via "The Daily Swig".
Patched bug could have leaked credentials๐ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Mastodon users vulnerable to password-stealing attacks
Patched bug could have leaked credentials
๐ด Nasty SQL Injection Bug in Zendesk Endangers Sensitive Customer Data ๐ด
๐ Read
via "Dark Reading".
The API-related vulnerabilities put conversations, email addresses, tickets, and more in danger of exposure via the Zendesk Explore reporting service.๐ Read
via "Dark Reading".
Dark Reading
Nasty SQL Injection Bug in Zendesk Endangers Sensitive Customer Data
The API-related vulnerabilities put conversations, email addresses, tickets, and more in danger of exposure via the Zendesk Explore reporting service.
๐ด Yakima Neighborhood Health Services Notice of Data Security Incident ๐ด
๐ Read
via "Dark Reading".
.๐ Read
via "Dark Reading".
Dark Reading
Yakima Neighborhood Health Services Notice of Data Security Incident
.
๐ด Red Canary Provides First-Ever MITRE Engenuityโข ATT&CKยฎ Evaluations for Managed Services ๐ด
๐ Read
via "Dark Reading".
.๐ Read
via "Dark Reading".
Dark Reading
Red Canary Provides First-Ever MITRE Engenuityโข ATT&CKยฎ Evaluations for Managed Services
.
โ๏ธ Top Zeus Botnet Suspect โTankโ Arrested in Geneva โ๏ธ
๐ Read
via "Krebs on Security".
Vyacheslav โTankโ Penchukov, the accused 40-year-old Ukrainian leader of a prolific cybercriminal group that stole tens of millions of dollars from small to mid-sized businesses in the United States and Europe, has been arrested in Switzerland, according to multiple sources.๐ Read
via "Krebs on Security".
Krebs on Security
Top Zeus Botnet Suspect โTankโ Arrested in Geneva
Vyacheslav โTankโ Penchukov, the accused 40-year-old Ukrainian leader of a prolific cybercriminal group that stole tens of millions of dollars from small to mid-sized businesses in the United States and Europe, has been arrested in Switzerland, accordingโฆ
๐๏ธ Zendesk Explore flaws opened the door to account pillage ๐๏ธ
๐ Read
via "The Daily Swig".
Patched SQLi and logical access vulnerabilities posed serious risk๐ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Zendesk Explore flaws opened the door to account pillage
Patched SQLi and logical access vulnerabilities posed serious risk