πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
‼️CVE-2023-49552‼️

An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjsopjsonstringify function in the msj.c file.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-49553‼️

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjsdestroy function in the msj.c file.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-49554‼️

Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the dodirective function in the modulespreprocsnasmnasmpp.c component.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-49555‼️

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expandsmacro function in the modulespreprocsnasmnasmpp.c component.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-49556‼️

Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the exprdeleteterm function in the libyasmexpr.c component.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-49557‼️

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasmsectionbcsfirst function in the libyasmsection.c component.

πŸ“– Read more

Via "National Vulnerability Database"
‼️CVE-2023-49558‼️

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expandmmacparams function in the modulespreprocsnasmnasmpp.c component.

πŸ“– Read more

Via "National Vulnerability Database"
πŸ–‹οΈ DOJ Slams XCast with $10 Million Fine Over Massive Illegal Robocall Operation πŸ–‹οΈ

The U.S. Department of Justice (DoJ) on Tuesday said it reached a settlement with VoIP service provider XCast over allegations that it facilitated illegal telemarketing campaigns since at least January 2018, in contravention of the Telemarketing Sales Rule (TSR).In addition to prohibiting the company from violating the law, the stipulated order requires it to meet other compliance measures,

πŸ“– Read

via "The Hacker News".
πŸ“” VoIP Firm XCast Agrees to Settle $10m Illegal Robocall Case πŸ“”

California-based XCast Labs says it will settle FTC charges of facilitating illegal robocalls

πŸ“– Read

via "Infosecurity Magazine".
🦿 TechRepublic Premium Editorial Calendar: Policies, Checklists, Hiring Kits and Glossaries for Download 🦿

TechRepublic Premium content helps you solve your toughest IT issues and jump-start your career or next project.

πŸ“– Read

via "Tech Republic".
πŸ“” Xerox Business Solutions Reveals Security Breach πŸ“”

Imaging giant Xerox says it suffered a security incident, as ransomware group INC Ransom claims scalp

πŸ“– Read

via "Infosecurity Magazine".
❀2
πŸ“” Russia Spies on Kyiv Defenses via Hacked Cameras Before Missile Strikes πŸ“”

Ukraine’s security services revealed Russia has hacked surveillance cameras to spy on air defense activities and critical infrastructure in Kyiv ahead of missile strikes

πŸ“– Read

via "Infosecurity Magazine".
❀1
πŸ–‹οΈ 5 Ways to Reduce SaaS Security Risks πŸ–‹οΈ

As technology adoption has shifted to be employee-led, just in time, and from any location or device, IT and security teams have found themselves contending with an ever-sprawling SaaS attack surface, much of which is often unknown or unmanaged. This greatly increases the risk of identity-based threats, and according to a recent report from CrowdStrike, 80% of breaches today use compromised

πŸ“– Read

via "The Hacker News".
πŸ–‹οΈ SMTP Smuggling: New Flaw Lets Attackers Bypass Security and Spoof Emails πŸ–‹οΈ

A new exploitation technique called Simple Mail Transfer Protocol (SMTP) smuggling can be weaponized by threat actors to send spoofed emails with fake sender addresses while bypassing security measures."Threat actors could abuse vulnerable SMTP servers worldwide to send malicious emails from arbitrary email addresses, allowing targeted phishing attacks," Timo Longin, a senior security

πŸ“– Read

via "The Hacker News".
πŸ“’ 'Local' machine learning promises to cut the cost of AI development in 2024 πŸ“’

Local machine learning inferencing will be a key trend in the year ahead, according to Hugging Face CTO Julien Chaumond

πŸ“– Read

via "ITPro".
πŸ“’ BT misses key Huawei kit removal deadline, but the telco is β€œalmost over the line” πŸ“’

BT is still reliant on non-compliant Huawei equipment for 2G and 3G services

πŸ“– Read

via "ITPro".
πŸ“’ Use of generative AI in the legal profession accelerating despite accuracy concerns πŸ“’

The use of generative AI in the legal profession has been a point of controversy amid concerns over accuracy

πŸ“– Read

via "ITPro".
πŸ–‹οΈ Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset πŸ–‹οΈ

Information stealing malware are actively taking advantage of an undocumented Google OAuth endpoint named MultiLogin to hijack user sessions and allow continuous access to Google services even after a password reset.According to CloudSEK, the critical exploit facilitates session persistence and cookie generation, enabling threat actors to maintain access to a valid session in an

πŸ“– Read

via "The Hacker News".
πŸ“” Fake and Stolen X Gold Accounts Flood Dark Web πŸ“”

CloudSEK explored some of the techniques threat actors have been using to forge or steal X Gold accounts since Elon Musk’s firm introduced its new verified accounts program

πŸ“– Read

via "Infosecurity Magazine".
πŸ“’ SentinelOne acquires PingSafe to drive cloud security capabilities πŸ“’

PingSafe’s cloud native application protection (CNAPP) solution will be integrated into the SentinelOne Singularity Platform

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ Brad Smith backtracks on CMA spat after 2023 regulatory battle πŸ“’

Brad Smith says the CMA was "tough and fair" in its decision to initially block the deal

πŸ“– Read

via "ITPro".