πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Ibexa DXP patched for GraphQL password hash leak vulnerability πŸ—“οΈ

Organizations advised to mandate password resets out of caution

πŸ“– Read

via "The Daily Swig".
πŸ•΄ The Next Generation of Supply Chain Attacks Is Here to Stay πŸ•΄

With the proliferation of interconnected third-party applications, new strategies are needed to close the security gap.

πŸ“– Read

via "Dark Reading".
πŸ•΄ County of Tehama, Calif., Identifies and Addresses Data Security Incident πŸ•΄

The county reports unauthorized access to files in its Department of Social Services' systems between Nov. 18, 2021, and April 9. It has added enhanced alert and monitoring software and is offering complimentary credit monitoring and identity theft protection services to those whose personal information may have been compromised in the breach.

πŸ“– Read

via "Dark Reading".
⚠ Black Friday and retail season – watch out for PayPal β€œmoney request” scams ⚠

Don't let a keen eye for bargains lead you into risky online behaviour...

πŸ“– Read

via "Naked Security".
πŸ‘1
⚠ S3 Ep109: How one leaked email password could drain your business [Audio + Transcript] ⚠

Latest episode - listen now! Cybersecurity news plus loads of great advice...

πŸ“– Read

via "Naked Security".
πŸ‘1
β€Ό CVE-2022-45471 β€Ό

In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Palo Alto Networks Focuses on Secure Coding with $195M Cider Deal πŸ•΄

PAN plans to add Cider's CI/CD security platform to its Prisma Cloud suite of AppSec tools.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Secure Offboarding in the Spotlight as Tech Layoffs Mount πŸ•΄

A secure-by-design culture is needed to develop a comprehensive offboarding and identity management strategy that limits potential for broader compromise in case of unauthorized access.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-45474 β€Ό

drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45473 β€Ό

In drachtio-server 0.8.18, /var/log/drachtio has mode 0777 and drachtio.log has mode 0666.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44378 β€Ό

Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44204 β€Ό

D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44379 β€Ό

Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_service.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Amid Legal Fallout, Cyber Insurers Redefine State-Sponsored Attacks as Act of War πŸ•΄

As carriers rewrite their act-of-war exclusions following the NotPetya settlement between Mondelez and Zurich, organizations should read their cyber insurance policies carefully to see what is still covered.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Australia's Hack-Back Plan Against Cyberattackers Raises Familiar Concerns πŸ•΄

How far can its government β€” or any government or private company β€” go to proactively disrupt cyber threats without causing collateral damage?

πŸ“– Read

via "Dark Reading".
πŸ•΄ DEV-0569 Ransomware Group Remarkably Innovative, Microsoft Cautions πŸ•΄

Although consistently reliant on good old phishing to deliver Royal ransomware, researchers say DEV-0569 regularly uses new and creative discovery techniques to lure in new victims.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-41652 β€Ό

Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40686 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44820 β€Ό

Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=transactions/manage_transaction&id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44415 β€Ό

Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/view_mechanic.php?id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38974 β€Ό

Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.

πŸ“– Read

via "National Vulnerability Database".