πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-25956 β€Ό

Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS Provider versions before 7.2.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4105 β€Ό

Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion.This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ To Safeguard Critical Infrastructure, Go Back to Basics πŸ•΄

CISA's recently released cybersecurity performance goals can help lower risk and thwart the impact of cyberattacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ TikTok Ban Hits EU Commission Phones as Cybersecurity Worries Mount πŸ•΄

Employees of the EU Commission are no longer allowed to use the TikTok app thanks to concerns over data security.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-35369 β€Ό

Arbitrary File Read vulnerability found in Peacexie ImCat v.5.2 fixed in v.5.4 allows attackers to obtain sensitive information via the filtering_get_contents function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33387 β€Ό

Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33224 β€Ό

File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4203 β€Ό

A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34064 β€Ό

An issue found in Koel v.5.1.4 and before allows remote attackers to gain access to sensitive information via the login form parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35370 β€Ό

An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23205 β€Ό

An issue was discovered in lib60870 v2.3.2. There is a memory leak in lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0585 β€Ό

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Administrator role or above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43923 β€Ό

IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0586 β€Ό

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor+ role to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep123: Crypto company compromise kerfuffle [Audio + Text] ⚠

Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

πŸ“– Read

via "Naked Security".
πŸ‘1πŸ€”1
β€Ό CVE-2023-0481 β€Ό

In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Evaluating the Cyber War Set Off by Russian Invasion of Ukraine πŸ•΄

Preparation and cooperation helped to mitigate the worst of the digital damage, amid cyber sorties from all sides.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Who’s Behind the Botnet-Based Service BHProxies? β™ŸοΈ

A security firm has discovered that a five-year-old crafty botnet known as Mylobot appears to be powering a residential proxy service called BHProxies, which offers paying customers the ability to route their web traffic anonymously through compromised computers. Here’s a closer look at Mylobot, and a deep dive into who may be responsible for operating the BHProxies service.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ 'New Class of Bugs' in Apple Devices Opens the Door to Complete Takeover πŸ•΄

With the right kind of exploit, there's hardly any function, app, or bit of data an attacker couldn't access on your Mac, iPad, or iPhone.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA: Beware of DDoS, Web Defacements on Anniversary of Russian Invasion of Ukraine πŸ•΄

The Cybersecurity and Infrastructure Security Agency advises US and European nations to prepare for possible website attacks marking the Feb. 24 invasion of Ukraine by Russia.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Canadian Telecom Firm Telus Reportedly Investigating Breach πŸ•΄

A threat actor has leaked data β€” purportedly, samples of Telus employee payroll data and source code β€” on a hacker site.

πŸ“– Read

via "Dark Reading".