πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-28104 β€Ό

`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly affects websites with particularly large/complex graphql schemas. Users should upgrade to `silverstripe/graphql` 4.2.3 or 4.1.2 to remedy the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28110 β€Ό

Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. Prior to version 2.28.8, using illegal tokens to connect to a Kubernetes cluster through Koko can result in the execution of dangerous commands that may disrupt the Koko container environment and affect normal usage. The vulnerability has been fixed in v2.28.8.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ $3B Crypto-Mixer Money Laundering Operation Seized by Cops πŸ•΄

The 'ChipMixer' cryptocurrency service for cybercriminals was shut down by law enforcement, and its alleged operator has been charged.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-0811 β€Ό

Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1256 β€Ό

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Rubrik confirms data breach but evades Cl0p ransomware allegations πŸ“’

It admitted some data was stolen through the exploitation of a zero day in a third-party platform, but has declined to comment on rumours of Cl0p's involvement

πŸ“– Read

via "ITPro".
πŸ“’ Outlook zero day patch causes headaches for Windows admins πŸ“’

The patch comes along with Microsoft's monthly Patch Tuesday updates which fix 83 vulnerabilities and two total zero days

πŸ“– Read

via "ITPro".
πŸ“’ Network security musts: The seven point checklist πŸ“’

How to acquire and deploy your cloud-based network security solution

πŸ“– Read

via "ITPro".
πŸ“’ Analysing the economic benefits of Trend Micro Vision One πŸ“’

Trend Micro Vision One as a solution to cyber risks

πŸ“– Read

via "ITPro".
πŸ“’ A roadmap to Zero Trust with Cloudflare and CrowdStrike πŸ“’

Achieve end-to-end protection across endpoints, networks, and applications

πŸ“– Read

via "ITPro".
πŸ“’ Zscaler makes key hire as it looks to revamp its partner programme πŸ“’

Former Palo Alto Networks executive Karl Soderlund will work to modernise Zscaler's channel operations

πŸ“– Read

via "ITPro".
πŸ“’ Ring denies ALPHV ransomware attack πŸ“’

The ransomware group has claimed to be in possession of stolen Ring data, but provided no evidence

πŸ“– Read

via "ITPro".
πŸ“’ Achieving zero trust for corporate networks πŸ“’

Zero trust is a new way of thinking about information security

πŸ“– Read

via "ITPro".
πŸ“’ Orange Cyberdefense collaborates with Microsoft to release two new managed services πŸ“’

New managed workspace protection and XDR offerings aim to help businesses β€œstay ahead of threats”

πŸ“– Read

via "ITPro".
πŸ“’ ZTNA vs on-premises VPN πŸ“’

How ZTNA wins the network security game

πŸ“– Read

via "ITPro".
πŸ“’ Brand-new Emotet campaign socially engineers its way from detection πŸ“’

This latest resurgence follows a three-month hiatus and tricks users into re-enabling dangerous VBA macros

πŸ“– Read

via "ITPro".
πŸ“’ The WFH cyber security checklist πŸ“’

Ten ways to win the remote access game with ZTNA

πŸ“– Read

via "ITPro".
πŸ“’ SOC modernisation and and the role of XDR πŸ“’

Security operations remain challenging

πŸ“– Read

via "ITPro".
πŸ“’ Accelerating your IT transformation πŸ“’

How Cloudflare is innovating for CIOs to start 2023

πŸ“– Read

via "ITPro".
πŸ“’ Defending against malware attacks starts here πŸ“’

The ultimate guide to building your malware defence strategy

πŸ“– Read

via "ITPro".
πŸ“’ Meet the charity shaping Australia and New Zealand's data breach response πŸ“’

IDCARE is recruiting a reserve army to turbocharge the fightback against cyber crime not just in the region, but in the interests of victims all over the world

πŸ“– Read

via "ITPro".
πŸ‘1