πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-46059 β€Ό

Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted payload to the Service, and website URL to Ping parameters of the admin/trackback.php component.

πŸ“– Read

via "National Vulnerability Database".
🦿 Generative AI Can Write Phishing Emails, But Humans Are Better At It, IBM X-Force Finds 🦿

Hacker Stephanie "Snow" Carruthers and her team found phishing emails written by security researchers saw a 3% better click rate than phishing emails written by ChatGPT.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 'Log in with...' Feature Allows Full Online Account Takeover for Millions πŸ•΄

Hundreds of millions of users of Grammarly, Vidio, and the Indonesian e-commerce giant Bukalapak are at risk for financial fraud and credential theft due to OAuth misfires -- and other online services likely have the same problems.

πŸ“– Read

via "Dark Reading".
πŸ•΄ It's Time to Establish the NATO of Cybersecurity πŸ•΄

Cybercriminals already operate across borders. Nations must do the same to protect their critical infrastructure, people, and technology from threats foreign and domestic.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cyberattacks on Kenya Drop in Third Quarter πŸ•΄

National response team attributes reduction to a cyber workforce with better training.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Strengthening Oman's Economic Backbone πŸ•΄

Creating a new regulatory framework to better secure Oman's banking system against future attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Do Small Companies Need Fractional AppSec Teams Akin to vCISOs? πŸ•΄

Zatik takes a fractional approach to AppSec leadership to help small firms access the expertise they need to build secure-by-design software.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Accenture Expands Cybersecurity Services Capabilities in Latin America With Acquisition of MNEMO Mexico πŸ•΄



πŸ“– Read

via "Dark Reading".
🦿 Cisco Patches Two Dangerous Zero-Day Vulnerabilities 🦿

The vulnerabilities, one of which was rated critical and one of which was rated highly severe, affect Cisco IOS XE software.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 2023 Ransomware Attacks Up More Than 95% Over 2022, According to Corvus Insurance Q3 Report πŸ•΄



πŸ“– Read

via "Dark Reading".
πŸ•΄ Tines Report Finds More than Half of Security Professionals Likely To Switch Jobs Next Year πŸ•΄



πŸ“– Read

via "Dark Reading".
πŸ•΄ This Cybersecurity Awareness Month, Don't Lose Sight of Human Risk πŸ•΄

Organizations should focus on four key areas to advance employee education and "cyber smartness."

πŸ“– Read

via "Dark Reading".
πŸ•΄ A Cybersecurity Framework for Mitigating Risks to Satellite Systems πŸ•΄

Cyber threats on satellite technology will persist and evolve. We need a comprehensive cybersecurity framework to protect them from attackers.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Winter Vivern APT Blasts Webmail Zero-Day Bug With One-Click Exploit πŸ•΄

A campaign targeting European governmental organizations and a think tank shows consistency from the low-profile threat group, which has ties to Belarus and Russia.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybersecurity Awareness Doesn't Cut It; It's Time to Focus on Behavior πŸ•΄

We have too much cybersecurity awareness. It's time to implement repeatable, real-world practice that ingrains positive habits and security behaviors.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Kazakh Attackers, Disguised as Azerbaijanis, Hit Former Soviet States πŸ•΄

The YoroTrooper group claims to be from Azerbaijan and even routes its phishing traffic through the former Soviet republic.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Virtual Alarm: VMware Issues Major Security Advisory πŸ•΄

VMWare vCenter Servers need immediate patch against critical RCE bug as race against threat actors begins.

πŸ“– Read

via "Dark Reading".
πŸ•΄ As Citrix Urges Its Clients to Patch, Researchers Release an Exploit πŸ•΄

In the race over Citrix's latest vulnerability, the bad guys have a huge head start, with broad implications for businesses and critical infrastructure providers worldwide.

πŸ“– Read

via "Dark Reading".
πŸ‘2
β€Ό CVE-2023-3010 β€Ό

Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1356 β€Ό

Reflected cross-site scripting in the StudentSearch component in IDAttendÒ€ℒs IDWeb application 3.1.052 and earlier allows hijacking of a userÒ€ℒs browsing session by attackers who have convinced the said user to click on a malicious link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3699 β€Ό

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to versionΓ‚ 1.3.1.2 andΓ‚ Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.

πŸ“– Read

via "National Vulnerability Database".