🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2022-44384

An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

📖 Read

via "National Vulnerability Database".
CVE-2022-40751

IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches. IBM X-Force ID: 236601.

📖 Read

via "National Vulnerability Database".
🕴 Iranian APT Actors Breached a US Government Network 🕴

CISA says Federal Civilian Executive Branch systems were compromised through a Log4Shell vulnerability in an unpatched VMware Horizon server.

📖 Read

via "Dark Reading".
CVE-2022-43142

A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.

📖 Read

via "National Vulnerability Database".
📢 Hundreds of thousands of Emotet attacks spotted daily after four-month hiatus 📢

The botnet that refuses to die returns again and is equipped with new payloads and tactics to evade detection

📖 Read

via "ITPro".
📢 Enabling secure hybrid learning in schools 📢

The importance of creating security awareness among key players

📖 Read

via "ITPro".
📢 Google agrees record $391.5m settlement in US digital tracking case 📢

The sum represents the largest settlement ever paid in a US digital privacy case which dates back to 2018

📖 Read

via "ITPro".
📢 The top 12 password-cracking techniques used by hackers 📢

Some of the most common, and most effective methods for stealing passwords

📖 Read

via "ITPro".
📢 NSA: Phase out memory-unsafe languages like C and C++ 📢

The US agency advises organisations to begin using languages like Rust, Java, and Swift

📖 Read

via "ITPro".
📢 How to react to a data breach 📢

Every business should have a data breach response plan, but when building one it can be difficult to know where to start

📖 Read

via "ITPro".
📢 Australia considers ransomware payment ban, additional Medibank files leaked 📢

REvil has claimed responsibility for the attack amidst continued refusal by Medibank to pay the ransom

📖 Read

via "ITPro".
📢 How to reduce cyber security costs for your business 📢

Nothing is off the table in a recession, but businesses must be careful to reduce cyber security costs without compromising on safety

📖 Read

via "ITPro".
📢 What is a router and how does it work? 📢

The role of a router in networking goes beyond simply allowing your business to access the web and stay connected with colleagues

📖 Read

via "ITPro".
📢 Ransomware: Why do businesses still pay up? 📢

Despite the guidance and best practice, an alarming proportion of businesses hit with ransomware simply pay to make it go away

📖 Read

via "ITPro".
📢 How to boot Windows 11 in Safe Mode 📢

Long-time Windows users will already be familiar with the feature, but novices may not be aware of how to boot in safe mode, especially in Windows 11

📖 Read

via "ITPro".
📢 GitHub launches private vulnerability reporting to secure the software supply chain 📢

The new platform aims to simplify vulnerability disclosure and minimise instances where researchers avoid reporting out of personal convenience

📖 Read

via "ITPro".
📢 The rising tide of no-hook phishing 📢

Not all phishing attacks rely on links or attachments, which means you’ll have to be extra careful

📖 Read

via "ITPro".
👍1
📢 Lenovo patches ThinkPad, Yoga, IdeaPad UEFI secure boot vulnerability 📢

Mistakenly used drivers could allow hackers to modify the secure boot process

📖 Read

via "ITPro".
CVE-2022-44725

OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).

📖 Read

via "National Vulnerability Database".
CVE-2022-43163

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php.

📖 Read

via "National Vulnerability Database".
CVE-2022-38461

Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).

📖 Read

via "National Vulnerability Database".