πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-22796 β€Ό

A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24322 β€Ό

A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21441 β€Ό

Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22797 β€Ό

An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a carefully crafted URL resulting in an open redirect vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22795 β€Ό

A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability All users running an affected release should either upgrade or use one of the workarounds immediately.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22799 β€Ό

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24689 β€Ό

An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24688 β€Ό

An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ NewsPenguin Goes Phishing for Maritime & Military Secrets πŸ•΄

A sophisticated cyber-espionage attack against high-value targets attending a maritime technology conference in Pakistan this weekend has been in the works since last year.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Reddit Breached With Stolen Employee Credentials πŸ•΄

Reddit code, internal documents, dashboards, and business systems were compromised in the cyberattack.

πŸ“– Read

via "Dark Reading".
πŸ“’ The case for an accelerated device refresh cycle πŸ“’

Achieving a more cost-effective device lifecycle overall

πŸ“– Read

via "ITPro".
πŸ“’ Why technology, cyber and privacy risk management are critical for digital transformation πŸ“’

How ServiceNow Integrated Risk Management helps you embrace the digital future

πŸ“– Read

via "ITPro".
πŸ“’ Automation: The key to optimised server management πŸ“’

Deliver modern digital end-user experiences, innovate with data, and more flexibly deliver IT services

πŸ“– Read

via "ITPro".
πŸ“’ Cyber resiliency and end-user performance πŸ“’

Reduce risk and deliver greater business success with cyber-resilience capabilities

πŸ“– Read

via "ITPro".
πŸ“’ What is spell-jacking? πŸ“’

Spell-jacking vulnerabilities are threatening to unwittingly leak data to third parties, undermining any drive to protect privacy

πŸ“– Read

via "ITPro".
πŸ“’ TD Synnex launches free security self-assessments for VMware partners πŸ“’

Partners can now offer clients three specially-designed surveys, worth tens of thousands, to help drive new business potential

πŸ“– Read

via "ITPro".
πŸ“’ PowerEdge - Cyber resilient infrastructure for a Zero Trust world πŸ“’

Combat threats with an in-depth security stance

πŸ“– Read

via "ITPro".
πŸ“’ ESXi ransomware campaign strikes Florida Supreme Court, worldwide universities πŸ“’

Threat actors show no sign of stopping following the widespread exploitation of the two-year-old vulnerability in VMware ESXi servers

πŸ“– Read

via "ITPro".
πŸ”₯1
πŸ•΄ Google Cloud Connects Chronicle to Health ISAC Feed πŸ•΄

Members of the Health-ISAC can ingest threat indicators directly into Chronicle to investigate whether the threat is present in their environment.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ OAuth β€˜masterclass’ crowned top web hacking technique of 2022 πŸ—“οΈ

Single sign-on and request smuggling to the fore in another stellar year for web security research

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Addressing the Elephant in the Room: Getting Developers & Security Teams to Work Together πŸ•΄

Bridging the divide between developers and security can create a culture change organically.

πŸ“– Read

via "Dark Reading".