πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2018-20104 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22960 β€Ό

Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21795 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21796.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21796 β€Ό

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21795.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21775 β€Ό

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22484 β€Ό

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to a polynomial time complexity issue in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. This vulnerability has been patched in 0.29.0.gfm.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21719 β€Ό

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22483 β€Ό

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to several polynomial time complexity issues in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. Various commands, when piped to cmark-gfm with large values, cause the running time to increase quadratically. These vulnerabilities have been patched in version 0.29.0.gfm.7.

πŸ“– Read

via "National Vulnerability Database".
⚠ Apple patches are out – old iPhones get an old zero-day fix at last! ⚠

Don't delay, especially if you're still running an iOS 12 device... please do it today!

πŸ“– Read

via "Naked Security".
πŸ‘2
β€Ό CVE-2023-22485 β€Ό

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29.0.gfm.7, a crafted markdown document can trigger an out-of-bounds read in the `validate_protocol` function. We believe this bug is harmless in practice, because the out-of-bounds read accesses `malloc` metadata without causing any visible damage.This vulnerability has been patched in 0.29.0.gfm.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23331 β€Ό

Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45639 β€Ό

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ IoT vendors faulted for slow progress in setting up vulnerability disclosure programs πŸ—“οΈ

Manufacturer complacency β€˜translates into an unacceptable risk for consumers’, warns security expert

πŸ“– Read

via "The Daily Swig".
πŸ‘4πŸ”₯1
β™ŸοΈ Administrator of RSOCKS Proxy Botnet Pleads Guilty β™ŸοΈ

Denis Emelyantsev, a 36-year-old Russian man accused of running a massive botnet called RSOCKS that stitched malware into millions of devices worldwide, pleaded guilty to two counts of computer crime violations in a California courtroom this week. The plea comes just months after Emelyantsev was extradited from Bulgaria, where he told investigators, β€œAmerica is looking for me because I have enormous information and they need it.”

πŸ“– Read

via "Krebs on Security".
πŸ”₯2πŸ‘1
⚠ Apple patches are out – old iPhones get an old zero-day fix at last! ⚠

Don't delay, especially if you're still running an iOS 12 device... please do it today!

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Yellowfin tackles auth bypass bug trio that opened door to RCE πŸ—“οΈ

Pre- and post-auth path to pwnage

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β™ŸοΈ Experian Glitch Exposing Credit Files Lasted 47 Days β™ŸοΈ

On Dec. 23, 2022, KrebsOnSecurity alerted big-three consumer credit reporting bureau Experian that identity thieves had worked out how to bypass its security and access any consumer's full credit report -- armed with nothing more than a person's name, address, date of birth, and Social Security number. Experian fixed the glitch, but remained silent about the incident for a month. This week, however, Experian acknowledged that the security failure persisted for nearly seven weeks, between Nov. 9, 2022 and Dec. 26, 2022.

πŸ“– Read

via "Krebs on Security".
πŸ‘1
πŸ—“οΈ Trellix automates tackling open source vulnerabilities at scale πŸ—“οΈ

More than 61,000 vulnerabilities patched and counting

πŸ“– Read

via "The Daily Swig".
πŸ‘1
⚠ GoTo admits: Customer cloud backups stolen together with decryption key ⚠

We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.

πŸ“– Read

via "Naked Security".
⚠ S3 Ep119: Breaches, patches, leaks and tweaks! [Audio + Text] ⚠

Lastest episode - listen now! (Or read the transcript.)

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Ruby on Rails apps vulnerable to data theft through Ransack search πŸ—“οΈ

Several applications were vulnerable to brute-force attacks; hundreds more could be at risk

πŸ“– Read

via "The Daily Swig".