πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Strengthening Oman's Economic Backbone πŸ•΄

Creating a new regulatory framework to better secure Oman's banking system against future attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Do Small Companies Need Fractional AppSec Teams Akin to vCISOs? πŸ•΄

Zatik takes a fractional approach to AppSec leadership to help small firms access the expertise they need to build secure-by-design software.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Accenture Expands Cybersecurity Services Capabilities in Latin America With Acquisition of MNEMO Mexico πŸ•΄



πŸ“– Read

via "Dark Reading".
🦿 Cisco Patches Two Dangerous Zero-Day Vulnerabilities 🦿

The vulnerabilities, one of which was rated critical and one of which was rated highly severe, affect Cisco IOS XE software.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 2023 Ransomware Attacks Up More Than 95% Over 2022, According to Corvus Insurance Q3 Report πŸ•΄



πŸ“– Read

via "Dark Reading".
πŸ•΄ Tines Report Finds More than Half of Security Professionals Likely To Switch Jobs Next Year πŸ•΄



πŸ“– Read

via "Dark Reading".
πŸ•΄ This Cybersecurity Awareness Month, Don't Lose Sight of Human Risk πŸ•΄

Organizations should focus on four key areas to advance employee education and "cyber smartness."

πŸ“– Read

via "Dark Reading".
πŸ•΄ A Cybersecurity Framework for Mitigating Risks to Satellite Systems πŸ•΄

Cyber threats on satellite technology will persist and evolve. We need a comprehensive cybersecurity framework to protect them from attackers.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Winter Vivern APT Blasts Webmail Zero-Day Bug With One-Click Exploit πŸ•΄

A campaign targeting European governmental organizations and a think tank shows consistency from the low-profile threat group, which has ties to Belarus and Russia.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybersecurity Awareness Doesn't Cut It; It's Time to Focus on Behavior πŸ•΄

We have too much cybersecurity awareness. It's time to implement repeatable, real-world practice that ingrains positive habits and security behaviors.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Kazakh Attackers, Disguised as Azerbaijanis, Hit Former Soviet States πŸ•΄

The YoroTrooper group claims to be from Azerbaijan and even routes its phishing traffic through the former Soviet republic.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Virtual Alarm: VMware Issues Major Security Advisory πŸ•΄

VMWare vCenter Servers need immediate patch against critical RCE bug as race against threat actors begins.

πŸ“– Read

via "Dark Reading".
πŸ•΄ As Citrix Urges Its Clients to Patch, Researchers Release an Exploit πŸ•΄

In the race over Citrix's latest vulnerability, the bad guys have a huge head start, with broad implications for businesses and critical infrastructure providers worldwide.

πŸ“– Read

via "Dark Reading".
πŸ‘2
β€Ό CVE-2023-3010 β€Ό

Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1356 β€Ό

Reflected cross-site scripting in the StudentSearch component in IDAttendÒ€ℒs IDWeb application 3.1.052 and earlier allows hijacking of a userÒ€ℒs browsing session by attackers who have convinced the said user to click on a malicious link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3699 β€Ό

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to versionΓ‚ 1.3.1.2 andΓ‚ Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38484 β€Ό

An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setup menu in AgeVolt Portal prior to version 0.1. A remote authenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with web server privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20273 β€Ό

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39734 β€Ό

The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39733 β€Ό

The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40413 β€Ό

The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. An app may be able to read sensitive location information.

πŸ“– Read

via "National Vulnerability Database".