๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด How Tech Companies Can Slow Down Spike in Breaches ๐Ÿ•ด

Cybercrime continues to evolve โ€” and shows no signs of slowing down.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ—“๏ธ Mastodon vulnerable to multiple system configuration problems ๐Ÿ—“๏ธ

The whole toot

๐Ÿ“– Read

via "The Daily Swig".
๐Ÿ•ด Google Blocks 231B Spam, Phishing Emails in Past 2 Weeks ๐Ÿ•ด

Google Workspace's team is seeing a spike in phishing and spam hitting Gmail โ€” up 10% in just the last two weeks.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Enterprises Pay $1,200 Per Employee Annually to Fight Cyberattacks Against Cloud Collab Apps ๐Ÿ•ด

Orgs are in the middle of a rapid increase in the use of new collaboration tools to serve the needs of an increasingly dispersed workforce โ€” and they're paying a very real security price.

๐Ÿ“– Read

via "Dark Reading".
โš  How social media scammers buy time to steal your 2FA codes โš 

The warning is hosted on a real Facebook page; the phishing uses HTTPS via a real Google server... but the content is all fake

๐Ÿ“– Read

via "Naked Security".
๐Ÿ‘1
โ€ผ CVE-2022-44202 โ€ผ

D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-41952 โ€ผ

Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) bytes have been downloaded, which can in some cases lead to long-lived connections towards the streaming media server (for instance, Icecast). This can cause excessive traffic and connections toward such servers if their stream URL is, for example, posted to a large room with many Synapse instances with URL preview enabled. Version 1.52.0 implements a timeout mechanism which will terminate URL preview connections after 30 seconds. Since generating URL previews for media streams is not supported and always fails, 1.53.0 additionally implements an allow list for content types for which Synapse will even attempt to generate a URL preview. Upgrade to 1.53.0 to fully resolve the issue. As a workaround, turn off URL preview functionality by setting `url_preview_enabled: false` in the Synapse configuration file.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-44807 โ€ผ

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-44737 โ€ผ

Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) รขโ‚ฌโ€œ Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-44804 โ€ผ

D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-44801 โ€ผ

D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-44806 โ€ผ

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-44201 โ€ผ

D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-44808 โ€ผ

A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-44184 โ€ผ

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  How to hack an unpatched Exchange server with rogue PowerShell code โš 

Review your servers, your patches and your authentication policies - there's a proof-of-concept out

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด Cyber Due Diligence in M&As Uncovers Threats, Improves Valuations ๐Ÿ•ด

To get the full picture, companies need to look into the cybersecurity history and practices of the business they're acquiring.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด How Work From Home Shaped the Road to SASE for Enterprises ๐Ÿ•ด

As SASE adoption grows, with its allure of simplified protection via one network and security experience for hybrid workers, remember: Have an overall plan, integrate and migrate to scale usage, and start small.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-39067 โ€ผ

There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacker could use the vulnerability to perform a denial of service attack.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-41950 โ€ผ

super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permissions. Note: this vulnerability only affects Linux and Mac OS systems. Users should upgrade to super-xray 0.3-beta.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-39070 โ€ผ

There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.

๐Ÿ“– Read

via "National Vulnerability Database".