πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ S3 Ep138: I like to MOVEit, MOVEit ⚠

Backdoors, exploits, and Little Bobby Tables. Listen now! (Full transcript available...)

πŸ“– Read

via "Naked Security".
πŸ•΄ Cl0P Gang Sat on Exploit for MOVEit Flaw for Nearly 2 Years πŸ•΄

Over that time, the group carried multiple tests to see if the exploit worked and to identify potential victims. It was like "turning the doorknob" to check for access, a researcher says.

πŸ“– Read

via "Dark Reading".
⚠ Thoughts on scheduled password changes (don’t call them rotations!) ⚠

Does swapping your password regularly make it a better password?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-2121 β€Ό

Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 3 Elite Communication Skills to Help Security Pros Get Projects Funded πŸ•΄

It's not enough to know how to better protect the enterprise β€” you have to be able to convince decision-makers that your plans are necessary.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-29712 β€Ό

Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the X-Rewrite-URL parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29714 β€Ό

Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via the username, password, and language cookies parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 'Asylum Ambuscade' Cyberattackers Blend Financial Heists & Cyber Espionage πŸ•΄

In a rare mix of motivations, the cyberattack group has been linked to both financial cybercrime and political spying efforts on governments.

πŸ“– Read

via "Dark Reading".
πŸ•΄ DOS Attacks Dominate, but System Intrusions Cause Most Pain πŸ•΄

In the latest Verizon "Data Breach Investigations Report," denial-of-service attacks are the most common type of security incident, but when it comes to breaches, nearly four-in-ten attackers compromise systems.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Brand-New Security Bugs Affect All MOVEit Transfer Versions πŸ•΄

Progress has issued a second patch for additional SQL flaws that are distinct from the zero-day that Cl0p ransomware gang is exploiting.

πŸ“– Read

via "Dark Reading".
⚠ Thoughts on scheduled password changes (don’t call them rotations!) ⚠

Does swapping your password regularly make it a better password?

πŸ“– Read

via "Naked Security".
⚠ More MOVEit mitigations: new patches published for further protection ⚠

Good news... more patches, this time available proactively

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-29752 β€Ό

An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29755 β€Ό

An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Passkeys See Fresh Momentum With New Pilot Programs πŸ•΄

Apple adds API that will enable sharing of passkeys across platforms, and Google offers passkey authentication in beta for Google Workspace and Google Cloud.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-3188 β€Ό

Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3191 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3190 β€Ό

Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3192 β€Ό

Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25912 β€Ό

The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and internal device values.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22586 β€Ό

The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter.

πŸ“– Read

via "National Vulnerability Database".