πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-24107 β€Ό

hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Cisco ClamAV anti-malware scanner vulnerable to serious security flaw πŸ—“οΈ

Patch released for bug that poses a critical risk to vulnerable technologies

πŸ“– Read

via "The Daily Swig".
πŸ‘2πŸ”₯1
πŸ•΄ Exploit Code Released for Critical Fortinet RCE Bug πŸ•΄

Organizations are urged to update to the latest versions of FortiNAC to patch a flaw that allows unauthenticated attackers to write arbitrary files on the system.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Trend Micro Acquires SOC Technology Expert Anlyz πŸ•΄

Technology tuck-in enhances industry's broadest XDR security platform.

πŸ“– Read

via "Dark Reading".
πŸ›  Zeek 5.0.7 πŸ› 

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. While focusing on network security monitoring, Zeek provides a comprehensive platform for more general network traffic analysis as well. Well grounded in more than 15 years of research, Zeek has successfully bridged the traditional gap between academia and operations since its inception. Today, it is relied upon operationally in particular by many scientific environments for securing their cyber-infrastructure. Zeek's user community includes major universities, research labs, supercomputing centers, and open-science communities. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
πŸ‘1
β€Ό CVE-2022-41217 β€Ό

Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41216 β€Ό

Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23063 β€Ό

Cellinx NVT v1.0.6.002b is vulnerable to local file disclosure.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Phishing Fears Ramp Up on Email, Collaboration Platforms πŸ•΄

It's a banner year for attacks coming through traditional email as well as newer collaboration technologies, such as Slack and Microsoft Teams. What's next?

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google Delivers Record-Breaking $12M in Bug Bounties πŸ•΄

Google's Android and Chrome Vulnerability Reward Programs (VRPs) in particular saw hundreds of valid reports and payouts for security vulnerabilities discovered by ethical hackers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Headwinds Don't Have to Be a Drag on Your Security Effectiveness πŸ•΄

Despite increased threats, an uncertain economy, and increasing automation, your organization can still thrive.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-43870 β€Ό

IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41566 β€Ό

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 5.6.0 and below.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23040 β€Ό

TP-Link router TL-WR940N V6 3.19.1 Build 180119 uses a deprecated MD5 algorithm to hash the admin password used for basic authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43873 β€Ό

An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute code and escalate their privilege on the system. IBM X-Force ID: 239847.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23039 β€Ό

An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41567 β€Ό

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0960 β€Ό

A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config.ftp.php of the component Picture Management. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-221630 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41565 β€Ό

The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.21 and below, versions 6.0.11 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.2.0 and below.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26214 β€Ό

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

πŸ“– Read

via "National Vulnerability Database".