πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Walking the line: GitOps and Shift Left security πŸ“’

Scalable, developer-centric supply chain security solutions

πŸ“– Read

via "ITPro".
πŸ“’ Beat cyber criminals at their own game πŸ“’

A guide to winning the vulnerability race and protection your organization

πŸ“– Read

via "ITPro".
πŸ“’ Off-the-shelf ransomware is spurring a new era in the Ukraine war πŸ“’

Experts agreed Russian forces could be overwhelmed, forced to use less sophisticated tools to meet the regime's demands

πŸ“– Read

via "ITPro".
πŸ“’ Quantifying the public vulnerability market: 2022 edition πŸ“’

An analysis of vulnerability disclosures, impact severity, and product analysis

πŸ“– Read

via "ITPro".
πŸ“’ Three ways to evolve your security operations πŸ“’

Why current approaches aren’t working

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-1767 β€Ό

The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023. A feature of Snyk Advisor is to display the contents of a scanned package's Readme on its package health page. An attacker could create a package in NPM with an associated markdown README file containing XSS-able HTML tags. Upon Snyk Advisor importing the package, the XSS would run each time an end user browsed to the package's page on Snyk Advisor.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Newer Authentication Tech a Priority for 2023 πŸ•΄

Organizations are planning on newer multifactor authentication methods such as invisible MFA and passwordless, says SecureAuth in its State of Authentication report.

πŸ“– Read

via "Dark Reading".
πŸ•΄ GPT-4 Provides Improved Answers While Posing New Questions πŸ•΄

As is typical with emerging technologies, both innovators and regulators struggle with developments in generative AI, much less the rules that should govern its use.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24109 β€Ό

An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent with a different key, and then remove the duplicate one. This will remove the flow rules of the intent, even though the intent still exists in the controller.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29604 β€Ό

An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. Improper handling of case sensitivity causes inconsistency between intent and flow rules in the network.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38363 β€Ό

An issue was discovered in ONOS 2.5.1. In IntentManager, the install-requested intent (which causes an exception) remains in pendingMap (in memory) forever. Deletion is possible neither by a user nor by the intermittent Intent Cleanup process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29609 β€Ό

An issue was discovered in ONOS 2.5.1. An intent with the same source and destination shows the INSTALLING state, indicating that its flow rules are installing. Improper handling of such an intent is misleading to a network operator.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24035 β€Ό

An issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topology (e.g., link failure). In combination with other applications, it could lead to a failure of network management.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29607 β€Ό

An issue was discovered in ONOS 2.5.1. Modification of an existing intent to have the same source and destination shows the INSTALLED state without any flow rule. Improper handling of such an intent is misleading to a network operator.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29944 β€Ό

An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of paths installed by intents. An existing intents does not redirect to a new path, even if a new intent that shares the path with higher priority is installed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29608 β€Ό

An issue was discovered in ONOS 2.5.1. An intent with a port that is an intermediate point of its path installs an invalid flow rule, causing a network loop.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38364 β€Ό

An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of flow rules installed by intents. A remote attacker can install or remove a new intent, and consequently modify or delete the existing flow rules related to other intents.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29605 β€Ό

An issue was discovered in ONOS 2.5.1. IntentManager attempts to install the IPv6 flow rules of an intent into an OpenFlow 1.0 switch that does not support IPv6. Improper handling of the difference in capabilities of the intent and switch is misleading to a network operator.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29606 β€Ό

An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers causes inconsistency between intent and flow rules in the network.

πŸ“– Read

via "National Vulnerability Database".
⚠ Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security ⚠

Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)

πŸ“– Read

via "Naked Security".
πŸ•΄ Global Spyware Attacks Spotted Against Both New & Old iPhones πŸ•΄

Campaigns that wielded NSO Group's Pegasus against high-risk users over a six-month period demonstrate the growing sophistication and relentless nature of spyware actors.

πŸ“– Read

via "Dark Reading".