π΄ AUVSI Launches Green UAS Cybersecurity Certification Program For Commercial Drones π΄
π Read
via "Dark Reading".
π Read
via "Dark Reading".
Dark Reading
AUVSI Launches Green UAS Cybersecurity Certification Program For Commercial Drones
ARLINGTON, VA, USA, February 23, 2023 -- Today, AUVSI announced the launch of Green UAS, a new program to expand the number of commercial Uncrewed Aircraft Systems (UAS) that have been verified to meet the highest levels of cybersecurity and National Defenseβ¦
π΄ Student Medical Records Exposed After LAUSD Breach π΄
π Read
via "Dark Reading".
"Hundreds" of special education students' psych records have turned up on the Dark Web. School records like these are covered by FERPA, not HIPAA, so parents have little recourse.π Read
via "Dark Reading".
Dark Reading
Student Medical Records Exposed After LAUSD Breach
"Hundreds" of special education students' psych records have turned up on the Dark Web. School records like these are covered by FERPA, not HIPAA, so parents have little recourse.
π΄ Pirated Final Cut Pro for macOS Offers Stealth Malware Delivery π΄
π Read
via "Dark Reading".
The number of people who have made the weaponized software available for sharing via torrent suggests that many unsuspecting victims may have downloaded the XMRig coin miner.π Read
via "Dark Reading".
Dark Reading
Pirated Final Cut Pro for macOS Offers Stealth Malware Delivery
The number of people who have made the weaponized software available for sharing via torrent suggests that many unsuspecting victims may have downloaded the XMRig coin miner.
βΌ CVE-2022-46785 βΌ
π Read
via "National Vulnerability Database".
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).π Read
via "National Vulnerability Database".
βΌ CVE-2022-46784 βΌ
π Read
via "National Vulnerability Database".
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)π Read
via "National Vulnerability Database".
βΌ CVE-2023-0755 βΌ
π Read
via "National Vulnerability Database".
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25823 βΌ
π Read
via "National Vulnerability Database".
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creating a Gradio app and then setting `share=True`), a private SSH key is sent to any user that connects to the Gradio machine, which means that a user could access other users' shared Gradio demos. From there, other exploits are possible depending on the level of access/exposure the Gradio app provides. This issue is patched in version 3.13.1, however, users are recommended to update to 3.19.1 or later where the FRP solution has been properly tested.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36231 βΌ
π Read
via "National Vulnerability Database".
pdf_info 0.5.3 is vulnerable to Command Execution.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25824 βΌ
π Read
via "National Vulnerability Database".
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered an endless loop retrying the read operation, consuming CPU resources. This could be exploited for denial of service attacks. If trace level logging was enabled, it would also produce an excessive amount of log output during the loop, consuming disk space. The problem has been fixed in commit d7eec4e598158ab6a98bf505354e84352f9715ec, please update to version 0.12.1. There are no workarounds, users who cannot update should apply the errno fix detailed in the security advisory.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0754 βΌ
π Read
via "National Vulnerability Database".
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24205 βΌ
π Read
via "National Vulnerability Database".
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).π Read
via "National Vulnerability Database".
π΄ 87% of Container Images in Production Have Critical or High-Severity Vulnerabilities π΄
π Read
via "Dark Reading".
At the inaugural CloudNativeSecurityCon, DevSecOps practitioners discussed how to shore up the software supply chain.π Read
via "Dark Reading".
Dark Reading
87% of Container Images in Production Have Critical or High-Severity Vulnerabilities
At the inaugural CloudNativeSecurityCon, DevSecOps practitioners discussed how to shore up the software supply chain.
βΌ CVE-2023-24212 βΌ
π Read
via "National Vulnerability Database".
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23295 βΌ
π Read
via "National Vulnerability Database".
Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23296 βΌ
π Read
via "National Vulnerability Database".
Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26468 βΌ
π Read
via "National Vulnerability Database".
Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23294 βΌ
π Read
via "National Vulnerability Database".
Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.π Read
via "National Vulnerability Database".
π₯1
βΌ CVE-2023-26102 βΌ
π Read
via "National Vulnerability Database".
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototypeπ Read
via "National Vulnerability Database".
βΌ CVE-2022-46440 βΌ
π Read
via "National Vulnerability Database".
ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0995 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.π Read
via "National Vulnerability Database".