πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-43762 β€Ό

Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43763 β€Ό

Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ DOM XSS vulnerability in Gartner Peer Insights widget patched πŸ—“οΈ

Web attack vector closed after failed fix

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why ChatGPT Isn't a Death Sentence for Cyber Defenders πŸ•΄

Generative AI combined with user awareness training creates a security alliance that can let organizations work protected from ChatGPT.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2023-0747 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41620 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Mandos Encrypted File System Unattended Reboot Utility 1.8.16 πŸ› 

The Mandos system allows computers to have encrypted root file systems and at the same time be capable of remote or unattended reboots. The computers run a small client program in the initial RAM disk environment which will communicate with a server over a network. All network communication is encrypted using TLS. The clients are identified by the server using an OpenPGP key that is unique to each client. The server sends the clients an encrypted password. The encrypted password is decrypted by the clients using the same OpenPGP key, and the password is then used to unlock the root file system.

πŸ“– Read

via "Packet Storm Security".
πŸ›  OpenSSL Toolkit 1.1.1t πŸ› 

OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer and Transport Layer Security protocols with full-strength cryptography world-wide.

πŸ“– Read

via "Packet Storm Security".
πŸ›  OpenSSL Toolkit 3.0.8 πŸ› 

OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer and Transport Layer Security protocols with full-strength cryptography world-wide. The 3.x series is the current major version of OpenSSL.

πŸ“– Read

via "Packet Storm Security".
πŸ—“οΈ Second UK Computer Misuse Act consultation reflects β€˜very little progress’ πŸ—“οΈ

Campaigner bemoans glacial progress of review and urges government to set clear timetable

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2023-0748 β€Ό

Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ It Isn't Time to Worry About Quantum Computing Just Yet πŸ•΄

Don't let something that's a decade away distract you from today's cyber threats.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Gigamon Exits NDR Market, Sells ThreatINSIGHT Business to Fortinet πŸ•΄

Omdia has learned that Gigamon sold its ThreatINSIGHT NDR business to Fortinet for approximately $31 million. The deal highlights what may be a pivot point for the NDR market.

πŸ“– Read

via "Dark Reading".
πŸ•΄ GAO Calls for Action to Protect Cybersecurity of Critical Energy, Communications Networks πŸ•΄

Enhanced industrial control systems cybersecurity for energy and communications sector among top recommendations in new GAO cybersecurity assessment.

πŸ“– Read

via "Dark Reading".
πŸ•΄ SecuriThings Brings Managed Service Capabilities to Physical Security, With New Managed Service Platform πŸ•΄

Platform opens new opportunities for managed service providers to manage, visualize, and secure customer devices from a single pane of glass, including automated maintenance and other operations.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-0002 β€Ό

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯1
β€Ό CVE-2023-0001 β€Ό

An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0003 β€Ό

A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Skybox Security Appoints Cybersecurity Veteran Mordecai Rosen as CEO πŸ•΄

Skybox closes $50 million in financing to drive growth of its SaaS-based security platform.

πŸ“– Read

via "Dark Reading".