πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Schneider Power Meter Vulnerability Opens Door to Power Outages πŸ•΄

A severe security vulnerability allows credentials for the power meters to continuously transmit in cleartext, allowing device takeover.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Fresh Ransomware Gangs Emerge As Market Leaders Decline πŸ•΄

The ransomware landscape is energized with the emergence of smaller groups and new tactics, while established gangs like LockBit see fewer victims.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Jordanian Cyber Leaders Kick Off Cybersecurity Framework Development πŸ•΄

The nation of Jordan begins work on a national cybersecurity framework to align with international practices and better mitigate threats.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cymulate Announces Security Analytics for Continuous Threat Exposure Management πŸ•΄

New product provides customers with an attacker's view of their cyber resilience aligned to business context.

πŸ“– Read

via "Dark Reading".
πŸ•΄ eSentire's AI Investigator Chatbot Aids Human Response to Security Incidents πŸ•΄

The tool trained on the company's investigative cybersecurity services data set, and provides natural language responses to client queries, to improve response and remediation efforts.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34563 β€Ό

netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35166 β€Ό

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ An Analyst View of Gartner Security & Risk Management Summit 2023 πŸ•΄

As a former Gartner analyst, it was interesting to be on the other side, listening as others explored the impact of CEO and CIO priorities on security.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34340 β€Ό

Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo.This issue affects Apache Accumulo: 2.1.0.Accumulo 2.1.0 contains a defect in the user authentication process that may succeed when invalid credentials are provided. Users are advised to upgrade to 2.1.1.

πŸ“– Read

via "National Vulnerability Database".
⚠ ASUS warns router customers: Patch now, or block all inbound requests ⚠

"Do as we say, not as we do!" - The patches took ages to come out, but don't let that lure you into taking ages to install them.

πŸ“– Read

via "Naked Security".
❀1
πŸ“’ Standardized information sharing framework 'essential' for improving cyber security πŸ“’

Companies are already weathering the cyber storm, but more can be done to help recovery, experts say

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-34981 β€Ό

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.

πŸ“– Read

via "National Vulnerability Database".
⚠ β€œThe Ransomware Documentary” – brand new video series from Sophos starting now! ⚠

Get the full 360-degree view of ransomware

πŸ“– Read

via "Naked Security".
πŸ•΄ Placing People & Realism at the Center of Your Cybersecurity Strategy πŸ•΄

While it's impossible for an organization to be completely secure, there's no reason to be defenseless.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-27450 β€Ό

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka pluginΓ‚ <= 3.29.2 versions.

πŸ“– Read

via "National Vulnerability Database".
❀1
β€Ό CVE-2023-27443 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <=Γ‚ 2.9.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27432 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WpSimpleTools Manage Upload Limit plugin <=Γ‚ 1.0.4 versions.

πŸ“– Read

via "National Vulnerability Database".
❀2
πŸ•΄ Cyberattacks on OT, ICS Lay Groundwork for Kinetic Warfare πŸ•΄

Organizations need to start taking critical infrastructure threats seriously, as they could be a precursor to future, hybrid cyber-kinetic warfare attacks, experts warn.

πŸ“– Read

via "Dark Reading".
⚠ Beware bad passwords as attackers co-opt Linux servers into cybercrime ⚠

Did you prevent password-only logins on your SSH servers? On ALL of them? Are you sure about that?

πŸ“– Read

via "Naked Security".
πŸ•΄ Emerging Ransomware Group 8Base Doxxes SMBs Globally πŸ•΄

A threat you've never heard of is using double extortion attacks on mom-and-pop shops around the globe.

πŸ“– Read

via "Dark Reading".