πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-22799 β€Ό

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24689 β€Ό

An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24688 β€Ό

An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ NewsPenguin Goes Phishing for Maritime & Military Secrets πŸ•΄

A sophisticated cyber-espionage attack against high-value targets attending a maritime technology conference in Pakistan this weekend has been in the works since last year.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Reddit Breached With Stolen Employee Credentials πŸ•΄

Reddit code, internal documents, dashboards, and business systems were compromised in the cyberattack.

πŸ“– Read

via "Dark Reading".
πŸ“’ The case for an accelerated device refresh cycle πŸ“’

Achieving a more cost-effective device lifecycle overall

πŸ“– Read

via "ITPro".
πŸ“’ Why technology, cyber and privacy risk management are critical for digital transformation πŸ“’

How ServiceNow Integrated Risk Management helps you embrace the digital future

πŸ“– Read

via "ITPro".
πŸ“’ Automation: The key to optimised server management πŸ“’

Deliver modern digital end-user experiences, innovate with data, and more flexibly deliver IT services

πŸ“– Read

via "ITPro".
πŸ“’ Cyber resiliency and end-user performance πŸ“’

Reduce risk and deliver greater business success with cyber-resilience capabilities

πŸ“– Read

via "ITPro".
πŸ“’ What is spell-jacking? πŸ“’

Spell-jacking vulnerabilities are threatening to unwittingly leak data to third parties, undermining any drive to protect privacy

πŸ“– Read

via "ITPro".
πŸ“’ TD Synnex launches free security self-assessments for VMware partners πŸ“’

Partners can now offer clients three specially-designed surveys, worth tens of thousands, to help drive new business potential

πŸ“– Read

via "ITPro".
πŸ“’ PowerEdge - Cyber resilient infrastructure for a Zero Trust world πŸ“’

Combat threats with an in-depth security stance

πŸ“– Read

via "ITPro".
πŸ“’ ESXi ransomware campaign strikes Florida Supreme Court, worldwide universities πŸ“’

Threat actors show no sign of stopping following the widespread exploitation of the two-year-old vulnerability in VMware ESXi servers

πŸ“– Read

via "ITPro".
πŸ”₯1
πŸ•΄ Google Cloud Connects Chronicle to Health ISAC Feed πŸ•΄

Members of the Health-ISAC can ingest threat indicators directly into Chronicle to investigate whether the threat is present in their environment.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ OAuth β€˜masterclass’ crowned top web hacking technique of 2022 πŸ—“οΈ

Single sign-on and request smuggling to the fore in another stellar year for web security research

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Addressing the Elephant in the Room: Getting Developers & Security Teams to Work Together πŸ•΄

Bridging the divide between developers and security can create a culture change organically.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-0771 β€Ό

SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23698 β€Ό

Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24410 β€Ό

Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0774 β€Ό

A vulnerability has been found in SourceCodester Medical Certificate Generator App 1.0 and classified as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument lastname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-220558 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23592 β€Ό

WALLIX Access Manager 3.x through 4.0.x allows a remote attacker to access sensitive information.

πŸ“– Read

via "National Vulnerability Database".