πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Microsoft Disables MSIX App Installer Protocol Widely Used in Malware Attacks πŸ–‹οΈ

Microsoft on Thursday said it’s once again disabling the ms-appinstaller protocol handler by default following its abuse by multiple threat actors to distribute malware.β€œThe observed threat actor activity abuses the current implementation of the ms-appinstaller protocol handler as an access vector for malware that may lead to ransomware distribution,” the Microsoft Threat Intelligence

πŸ“– Read

via "The Hacker News".
πŸ–‹οΈ CERT-UA Uncovers New Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK πŸ–‹οΈ

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new phishing campaign orchestrated by the Russia-linked APT28 group to deploy previously undocumented malware such as OCEANMAP, MASEPIE, and STEELHOOK to harvest sensitive information.The activity, which was detected by the agency between December 15 and 25, 2023, targets government entities

πŸ“– Read

via "The Hacker News".
πŸ•΄ UAE Banks on AI to Boost Cybersecurity πŸ•΄

The federation has formed partnerships to aid its cybersecurity ambitions as well, but aging legacy systems and a talent gap leave the UAE vulnerable to cyber-risks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ I Securely Resolve: CISOs, IT Security Leaders Share 2024 Resolutions πŸ•΄

As cybersecurity leaders confront ever more complex challenges, the new year offers security leaders a chance to strategically reevaluate and plan for 2024.

πŸ“– Read

via "Dark Reading".
πŸ–‹οΈ Albanian Parliament and One Albania Telecom Hit by Cyber Attacks πŸ–‹οΈ

The Assembly of the Republic of Albania and telecom company One Albania have been targeted by cyber attacks, the country’s National Authority for Electronic Certification and Cyber Security (AKCESK) revealed this week.β€œThese infrastructures, under the legislation in force, are not currently classified as critical or important information infrastructure,” AKCESK said.One Albania, which has

πŸ“– Read

via "The Hacker News".
πŸ–±οΈ A year in review: 10 of the biggest security incidents of 2023 πŸ–±οΈ

As we draw the curtain on another eventful year in cybersecurity, let’s review some of the high-profile cyber-incidents that occurred in 2023

πŸ“– Read

via "WeLiveSecurity - ESET".
πŸ•΄ Palo Alto Networks Closes Talon Cybersecurity Acquisition πŸ•΄

The Talon acquisition extends Palo Alto Networks' best-in-class SASE solution to help protect all managed and unmanaged devices.

πŸ“– Read

via "Dark Reading".
πŸ•΄ β€˜Operation Triangulation’ Spyware Attackers Bypass iPhone Memory Protections πŸ•΄

The Operation Triangulation attacks are abusing undocumented functions in Apple chips to circumvent hardware-based security measures.

πŸ“– Read

via "Dark Reading".
❀2πŸ”₯1
‼️CVE-2023-7143‼️

A vulnerability was found in codeprojects Client Details System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file adminregester.php. The manipulation of the argument fnamelnameemailcontact leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB249146 is the identifier assigned to this vulnerability.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-7144‼️

A vulnerability classified as critical has been found in gopeak MasterLab up to 3.3.10. This affects the function sqlInject of the file appctrlframeworkFeature.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB249147.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-23431‼️

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-23432‼️

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-23433‼️

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-23434‼️

Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-23435‼️

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-23436‼️

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-31292‼️

An issue was discovered in Sesami Cash Point Transport Optimizer CPTO 6.3.8.6 718, allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-31298‼️

Cross Site Scripting XSS vulnerability in Sesami Cash Point Transport Optimizer CPTO version 6.3.8.6 718, allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-31301‼️

Stored Cross Site Scripting XSS Vulnerability in Sesami Cash Point Transport Optimizer CPTO version 6.3.8.6 718, allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-7145‼️

A vulnerability classified as critical was found in gopeak MasterLab up to 3.3.10. This vulnerability affects the function sqlInject of the file appctrlFramework.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB249148.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-7146‼️

A vulnerability, which was classified as critical, has been found in gopeak MasterLab up to 3.3.10. This issue affects the function sqlInjectDelete of the file appctrlframeworkFeature.php of the component HTTP POST Request Handler. The manipulation of the argument phone leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB249149 was assigned to this vulnerability.

πŸ“– Read more

Via "National Vulnerability Database"
πŸ‘1