πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-44402 β€Ό

Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42891 β€Ό

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the websiteÒ€ℒs application pool.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42894 β€Ό

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Request Forgery (SSRF) vulnerability was identified in one of the web services exposed on the syngo Dynamics application that could allow for the leaking of NTLM credentials as well as local service enumeration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44384 β€Ό

An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40751 β€Ό

IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches. IBM X-Force ID: 236601.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Iranian APT Actors Breached a US Government Network πŸ•΄

CISA says Federal Civilian Executive Branch systems were compromised through a Log4Shell vulnerability in an unpatched VMware Horizon server.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-43142 β€Ό

A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Hundreds of thousands of Emotet attacks spotted daily after four-month hiatus πŸ“’

The botnet that refuses to die returns again and is equipped with new payloads and tactics to evade detection

πŸ“– Read

via "ITPro".
πŸ“’ Enabling secure hybrid learning in schools πŸ“’

The importance of creating security awareness among key players

πŸ“– Read

via "ITPro".
πŸ“’ Google agrees record $391.5m settlement in US digital tracking case πŸ“’

The sum represents the largest settlement ever paid in a US digital privacy case which dates back to 2018

πŸ“– Read

via "ITPro".
πŸ“’ The top 12 password-cracking techniques used by hackers πŸ“’

Some of the most common, and most effective methods for stealing passwords

πŸ“– Read

via "ITPro".
πŸ“’ NSA: Phase out memory-unsafe languages like C and C++ πŸ“’

The US agency advises organisations to begin using languages like Rust, Java, and Swift

πŸ“– Read

via "ITPro".
πŸ“’ How to react to a data breach πŸ“’

Every business should have a data breach response plan, but when building one it can be difficult to know where to start

πŸ“– Read

via "ITPro".
πŸ“’ Australia considers ransomware payment ban, additional Medibank files leaked πŸ“’

REvil has claimed responsibility for the attack amidst continued refusal by Medibank to pay the ransom

πŸ“– Read

via "ITPro".
πŸ“’ How to reduce cyber security costs for your business πŸ“’

Nothing is off the table in a recession, but businesses must be careful to reduce cyber security costs without compromising on safety

πŸ“– Read

via "ITPro".
πŸ“’ What is a router and how does it work? πŸ“’

The role of a router in networking goes beyond simply allowing your business to access the web and stay connected with colleagues

πŸ“– Read

via "ITPro".
πŸ“’ Ransomware: Why do businesses still pay up? πŸ“’

Despite the guidance and best practice, an alarming proportion of businesses hit with ransomware simply pay to make it go away

πŸ“– Read

via "ITPro".
πŸ“’ How to boot Windows 11 in Safe Mode πŸ“’

Long-time Windows users will already be familiar with the feature, but novices may not be aware of how to boot in safe mode, especially in Windows 11

πŸ“– Read

via "ITPro".
πŸ“’ GitHub launches private vulnerability reporting to secure the software supply chain πŸ“’

The new platform aims to simplify vulnerability disclosure and minimise instances where researchers avoid reporting out of personal convenience

πŸ“– Read

via "ITPro".
πŸ“’ The rising tide of no-hook phishing πŸ“’

Not all phishing attacks rely on links or attachments, which means you’ll have to be extra careful

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ Lenovo patches ThinkPad, Yoga, IdeaPad UEFI secure boot vulnerability πŸ“’

Mistakenly used drivers could allow hackers to modify the secure boot process

πŸ“– Read

via "ITPro".