πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-0052 β€Ό

SAUTER Controls Nova 200Γ’β‚¬β€œ220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an unauthorized user could access the system and modify the device configuration, which could result in the unauthorized user executing unrestricted malicious commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24028 β€Ό

In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22884 β€Ό

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0433 β€Ό

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ“’ European partners expect growth this year, here are three ways they will achieve it πŸ“’

It’s possible to achieve growth at a time of global economic turmoil, provided business objectives are fully aligned with the needs of customers

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ MSI to release securer BIOS settings after critical flaw discovered πŸ“’

The firm has admitted it essentially disabled Secure Boot on its motherboards in an attempt to improve customisability

πŸ“– Read

via "ITPro".
πŸ“’ Windows 11 System Restore bug preventing users from accessing apps πŸ“’

Microsoft has issued a series of workarounds for the issue which is affecting a range of apps including Office and Terminal

πŸ“– Read

via "ITPro".
πŸ“’ Royal Mail ransom note leaked, LockBit’s role remains uncertain πŸ“’

The prolific ransomware operation has denied involvement but researchers remain sceptical

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft releases scripts to restore shortcuts deleted in faulty Windows Defender update πŸ“’

However, some users have resorted to creating their own fixes as they’ve encountered Microsoft’s to be problematic

πŸ“– Read

via "ITPro".
πŸ“’ 'Highly evasive' polymorphic malware generated using ChatGPT πŸ“’

Researchers at CyberArk Labs developed a novel method to generate malware using text that goes largely undetected by signature-based antimalware products

πŸ“– Read

via "ITPro".
πŸ“’ Google Ads malvertising campaign prompts questions around Search security πŸ“’

A leading security researcher has called into question why Google still allows malware links to top search results

πŸ“– Read

via "ITPro".
πŸ“’ Meta sues β€˜data scraping for hire’ service that collected info on 600k users πŸ“’

Meta says tackling data scraping will require a β€œcollective effort” from platforms and policymakers

πŸ“– Read

via "ITPro".
πŸ“’ Windows Defender update deletes Start Menu, Taskbar, Desktop shortcuts πŸ“’

For now, it appears that administrators will have to manually recreate their shortcuts once the issue has been fixed

πŸ“– Read

via "ITPro".
πŸ“’ Hack The Box set to triple workforce and widen global expansion πŸ“’

CEO Haris Pylarinos told IT Pro the startup plans to accelerate international expansion and continue driving security skills awareness

πŸ“– Read

via "ITPro".
πŸ“’ T-Mobile breach leaves customers vulnerable to phishing πŸ“’

T-Mobile confirmed that while customer information was exposed, no financial data or company systems were compromised

πŸ“– Read

via "ITPro".
πŸ“’ Businesses must overhaul β€œoutdated” recruitment mindset to tackle dearth of privacy expertise πŸ“’

Like many other disciplines within IT, businesses are struggling to fill crucial positions for months at a time - an issue somewhat of their own making

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-22617 β€Ό

A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misconfigured domain, because QName minimization is used in QM fallback mode. This is fixed in 4.8.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24059 β€Ό

Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24058 β€Ό

Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0435 β€Ό

Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48281 β€Ό

processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image.

πŸ“– Read

via "National Vulnerability Database".