🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
📢 NSA: Phase out memory-unsafe languages like C and C++ 📢

The US agency advises organisations to begin using languages like Rust, Java, and Swift

📖 Read

via "ITPro".
📢 How to react to a data breach 📢

Every business should have a data breach response plan, but when building one it can be difficult to know where to start

📖 Read

via "ITPro".
📢 Australia considers ransomware payment ban, additional Medibank files leaked 📢

REvil has claimed responsibility for the attack amidst continued refusal by Medibank to pay the ransom

📖 Read

via "ITPro".
📢 How to reduce cyber security costs for your business 📢

Nothing is off the table in a recession, but businesses must be careful to reduce cyber security costs without compromising on safety

📖 Read

via "ITPro".
📢 What is a router and how does it work? 📢

The role of a router in networking goes beyond simply allowing your business to access the web and stay connected with colleagues

📖 Read

via "ITPro".
📢 Ransomware: Why do businesses still pay up? 📢

Despite the guidance and best practice, an alarming proportion of businesses hit with ransomware simply pay to make it go away

📖 Read

via "ITPro".
📢 How to boot Windows 11 in Safe Mode 📢

Long-time Windows users will already be familiar with the feature, but novices may not be aware of how to boot in safe mode, especially in Windows 11

📖 Read

via "ITPro".
📢 GitHub launches private vulnerability reporting to secure the software supply chain 📢

The new platform aims to simplify vulnerability disclosure and minimise instances where researchers avoid reporting out of personal convenience

📖 Read

via "ITPro".
📢 The rising tide of no-hook phishing 📢

Not all phishing attacks rely on links or attachments, which means you’ll have to be extra careful

📖 Read

via "ITPro".
👍1
📢 Lenovo patches ThinkPad, Yoga, IdeaPad UEFI secure boot vulnerability 📢

Mistakenly used drivers could allow hackers to modify the secure boot process

📖 Read

via "ITPro".
CVE-2022-44725

OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).

📖 Read

via "National Vulnerability Database".
CVE-2022-43163

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php.

📖 Read

via "National Vulnerability Database".
CVE-2022-38461

Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).

📖 Read

via "National Vulnerability Database".
CVE-2022-43162

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/view_test.php.

📖 Read

via "National Vulnerability Database".
CVE-2022-45072

Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.

📖 Read

via "National Vulnerability Database".
CVE-2022-42903

Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.

📖 Read

via "National Vulnerability Database".
CVE-2022-44001

An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.

📖 Read

via "National Vulnerability Database".
CVE-2022-43179

Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?page=user/manage_user&id=.

📖 Read

via "National Vulnerability Database".
CVE-2021-31608

Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.

📖 Read

via "National Vulnerability Database".
CVE-2022-45071

Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.

📖 Read

via "National Vulnerability Database".
CVE-2022-3090

Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are vulnerable to path traversal. When attempting to open a file using a specific path, the user's password hash is sent to an arbitrary host. This could allow an attacker to obtain user credential hashes.

📖 Read

via "National Vulnerability Database".