πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ In Memoriam: Remembering Those Who Passed πŸ•΄

Security stands on the shoulders of giants. We take a moment to remember their contributions toward keeping people, data, and systems safe.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-45911 β€Ό

An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which means that even if the attacker executes arbitrary JavaScript, they will not get any sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45913 β€Ό

An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via one of attributes in webmail URLs to execute arbitrary JavaScript code, leading to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2014-125053 β€Ό

A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading to version 1.3.1 is able to address this issue. The name of the patch is 0cdd1c388edf15089c3a7541cefe7756e560581d. It is recommended to upgrade the affected component. VDB-217582 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Play ransomware gang behind recent cyber attack on Rackspace πŸ“’

Rackspace said that β€œmore than half” of affected customers have regained access to data in the wake of the attack

πŸ“– Read

via "ITPro".
πŸ“’ The IT Pro Podcast: Going passwordless πŸ“’

Something you are, or something you have, could be more important than a password you know in the near future

πŸ“– Read

via "ITPro".
😱1
πŸ“’ Research: Luxury cars and emergency services vehicles vulnerable to remote takeover πŸ“’

A "global API issue" has been highlighted through months-long research into brands such as Ferrari and Mercedes-Benz, leaving owners open to hacking, account takeovers, and more

πŸ“– Read

via "ITPro".
πŸ“’ Cyber attack on car dealership Arnold Clark forces systems offline πŸ“’

The company was notified on 23 December about the suspicious incident and IT systems remain down, impacting customer-facing services

πŸ“– Read

via "ITPro".
πŸ“’ Podcast transcript: Going passwordless πŸ“’

Read the full transcript for this episode of the IT Pro Podcast

πŸ“– Read

via "ITPro".
πŸ“’ Rapid7 hires whistleblower Peiter "Mudge" Zatko a year after Twitter sacking πŸ“’

Zatko will advise clients at the security firm, in his first public role since launching his whistleblower campaign against Twitter

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ Six myths of SIEM πŸ“’

Things have changed when it comes to SIEM solutions

πŸ“– Read

via "ITPro".
πŸ“’ Shopify bets on 'Audiences' tool to combat Apple's tracking restrictions for retailers πŸ“’

The ecommerce giant hopes its millions of customers will benefit from the Apple-compliant customer-targeting capabilities

πŸ“– Read

via "ITPro".
πŸ“’ IDC MarketScape: Worldwide unified endpoint management services πŸ“’

2022 vendor assessment

πŸ“– Read

via "ITPro".
πŸ“’ Cyber attacks on UK organisations surged 77% in 2022, new research finds πŸ“’

The UK education sector saw a 237% increase in attacks compared to 2021

πŸ“– Read

via "ITPro".
πŸ“’ Unified Endpoint Management and Security in a work-from-anywhere world πŸ“’

Management and security activities are deeply intertwined, requiring integrated workflows between IT and security teams

πŸ“– Read

via "ITPro".
πŸ“’ WhatsApp to combat internet blackouts with proxy server support πŸ“’

The newest version of the world's most popular communications platform offers a new way for users to connect while bypassing blockades that aim to limit access to the outside world

πŸ“– Read

via "ITPro".
πŸ“’ Storage's role in addressing the challenges of ensuring cyber resilience πŸ“’

Understanding the role of data storage in cyber resiliency

πŸ“– Read

via "ITPro".
πŸ‘2
β€Ό CVE-2023-0112 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0106 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0107 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0110 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

πŸ“– Read

via "National Vulnerability Database".