πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-23659 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24384 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0988 β€Ό

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0. This issue affects some unknown processing of the file admin/ajax.php?action=save_user. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221681 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0867 β€Ό

Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24415 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud ChatBot ? plugin <= 4.2.8 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0815 β€Ό

Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ (ISC)Β² Opens Security Congress 2023 Call for Presentations πŸ•΄

(ISC)2 members and cybersecurity professionals worldwide are encouraged to share their expertise, best practices and experiences with their peers and career hopefuls.

πŸ“– Read

via "Dark Reading".
⚠ NPM JavaScript packages abused to create scambait links in bulk ⚠

Free spins? Bonus game points? Cheap social media followers? What harm could it possibly do if you just take a tiny little look?!

πŸ“– Read

via "Naked Security".
πŸ•΄ Why Are My Employees Integrating With So Many Unsanctioned SaaS Apps? πŸ•΄

Before adopting SaaS apps, companies should set security guardrails to vet new vendors and check security integration for misconfiguration risks.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep123: Crypto company compromise kerfuffle [Audio + Text] ⚠

Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

πŸ“– Read

via "Naked Security".
πŸ•΄ Metomic Raises $20 Million to Protect Sensitive Data in SaaS Applications πŸ•΄

As a data security solution focused solely on SaaS ecosystems, Metomic will use the Series A funding round to expand into the U.S.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cris Thomas: Space Rogue, From L0pht Hacker to IBM Security Influencer πŸ•΄

Security Pro File: The old-school hacker traces a path from young hardware tinkerer to senior cybersecurity executive.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Vault Vision Launches One Click Passwordless Logins With Passkey User Authentication πŸ•΄

Eliminate passwords in user authentication workflow with Vault Vision's passkey features like facial recognition, fingerprint and pin verification on all modern devices.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-2176 β€Ό

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Wiper Malware Surges Ahead, Spiking 53% in 3 Months πŸ•΄

Cybercriminals and hacktivists have joined state-backed actors in using sabotage-bent malware in destructive attacks, new report shows.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Unanswered Questions Cloud the Recent Targeting of an Asian Research Org πŸ•΄

A novel threat group, utilizing new malware, is out in the wild. But the who, what, where, and why are yet to be determined, and there's evidence of a false-flag operation.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Linux Foundation Europe Announces Formation of OpenWallet Foundation πŸ•΄

Diverse ecosystem of global technology, finance, and university leaders join as first OpenWallet Foundation Members, many more expected.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Cyberattack on Dole Causes Temporary Salad Shortage πŸ•΄

The produce company said it suffered a ransomware attack earlier this month.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-0597 β€Ό

A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected location in memory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20011 β€Ό

A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. If the affected user has administrative privileges, these actions could include modifying the system configuration and creating new privileged accounts.

πŸ“– Read

via "National Vulnerability Database".