🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
📢 Rapid7 hires whistleblower Peiter "Mudge" Zatko a year after Twitter sacking 📢

Zatko will advise clients at the security firm, in his first public role since launching his whistleblower campaign against Twitter

📖 Read

via "ITPro".
👍1
📢 Six myths of SIEM 📢

Things have changed when it comes to SIEM solutions

📖 Read

via "ITPro".
📢 Shopify bets on 'Audiences' tool to combat Apple's tracking restrictions for retailers 📢

The ecommerce giant hopes its millions of customers will benefit from the Apple-compliant customer-targeting capabilities

📖 Read

via "ITPro".
📢 IDC MarketScape: Worldwide unified endpoint management services 📢

2022 vendor assessment

📖 Read

via "ITPro".
📢 Cyber attacks on UK organisations surged 77% in 2022, new research finds 📢

The UK education sector saw a 237% increase in attacks compared to 2021

📖 Read

via "ITPro".
📢 Unified Endpoint Management and Security in a work-from-anywhere world 📢

Management and security activities are deeply intertwined, requiring integrated workflows between IT and security teams

📖 Read

via "ITPro".
📢 WhatsApp to combat internet blackouts with proxy server support 📢

The newest version of the world's most popular communications platform offers a new way for users to connect while bypassing blockades that aim to limit access to the outside world

📖 Read

via "ITPro".
📢 Storage's role in addressing the challenges of ensuring cyber resilience 📢

Understanding the role of data storage in cyber resiliency

📖 Read

via "ITPro".
👍2
CVE-2023-0112

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

📖 Read

via "National Vulnerability Database".
CVE-2023-0106

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

📖 Read

via "National Vulnerability Database".
CVE-2023-0107

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

📖 Read

via "National Vulnerability Database".
CVE-2023-0110

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

📖 Read

via "National Vulnerability Database".
CVE-2023-0111

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

📖 Read

via "National Vulnerability Database".
CVE-2023-0108

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

📖 Read

via "National Vulnerability Database".
CVE-2023-0113

A vulnerability was found in Netis Netcore Router. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-217591.

📖 Read

via "National Vulnerability Database".
CVE-2018-25069

A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The identifier VDB-217593 was assigned to this vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2014-125055

A vulnerability, which was classified as problematic, was found in agnivade easy-scrypt. Affected is the function VerifyPassphrase of the file scrypt.go. The manipulation leads to observable timing discrepancy. Upgrading to version 1.0.0 is able to address this issue. The name of the patch is 477c10cf3b144ddf96526aa09f5fdea613f21812. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217596.

📖 Read

via "National Vulnerability Database".
CVE-2020-36644

A vulnerability has been found in jamesmartin Inline SVG up to 1.7.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file lib/inline_svg/action_view/helpers.rb of the component URL Parameter Handler. The manipulation of the argument filename leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.7.2 is able to address this issue. The name of the patch is f5363b351508486021f99e083c92068cf2943621. It is recommended to upgrade the affected component. The identifier VDB-217597 was assigned to this vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2015-10019

A vulnerability, which was classified as problematic, has been found in foxoverflow MySimplifiedSQL. This issue affects some unknown processing of the file MySimplifiedSQL_Examples.php. The manipulation of the argument FirstName/LastName leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 3b7481c72786f88041b7c2d83bb4f219f77f1293. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217595.

📖 Read

via "National Vulnerability Database".
CVE-2023-0114

A vulnerability was found in Netis Netcore Router. It has been rated as problematic. Affected by this issue is some unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The identifier of this vulnerability is VDB-217592.

📖 Read

via "National Vulnerability Database".
CVE-2014-125057

A vulnerability was found in mrobit robitailletheknot. It has been classified as problematic. This affects an unknown part of the file app/filters.php of the component CSRF Token Handler. The manipulation of the argument _token leads to incorrect comparison. It is possible to initiate the attack remotely. The name of the patch is 6b2813696ccb88d0576dfb305122ee880eb36197. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217599.

📖 Read

via "National Vulnerability Database".