πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-4203 β€Ό

A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34064 β€Ό

An issue found in Koel v.5.1.4 and before allows remote attackers to gain access to sensitive information via the login form parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35370 β€Ό

An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23205 β€Ό

An issue was discovered in lib60870 v2.3.2. There is a memory leak in lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0585 β€Ό

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Administrator role or above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43923 β€Ό

IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0586 β€Ό

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor+ role to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep123: Crypto company compromise kerfuffle [Audio + Text] ⚠

Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

πŸ“– Read

via "Naked Security".
πŸ‘1πŸ€”1
β€Ό CVE-2023-0481 β€Ό

In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Evaluating the Cyber War Set Off by Russian Invasion of Ukraine πŸ•΄

Preparation and cooperation helped to mitigate the worst of the digital damage, amid cyber sorties from all sides.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Who’s Behind the Botnet-Based Service BHProxies? β™ŸοΈ

A security firm has discovered that a five-year-old crafty botnet known as Mylobot appears to be powering a residential proxy service called BHProxies, which offers paying customers the ability to route their web traffic anonymously through compromised computers. Here’s a closer look at Mylobot, and a deep dive into who may be responsible for operating the BHProxies service.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ 'New Class of Bugs' in Apple Devices Opens the Door to Complete Takeover πŸ•΄

With the right kind of exploit, there's hardly any function, app, or bit of data an attacker couldn't access on your Mac, iPad, or iPhone.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA: Beware of DDoS, Web Defacements on Anniversary of Russian Invasion of Ukraine πŸ•΄

The Cybersecurity and Infrastructure Security Agency advises US and European nations to prepare for possible website attacks marking the Feb. 24 invasion of Ukraine by Russia.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Canadian Telecom Firm Telus Reportedly Investigating Breach πŸ•΄

A threat actor has leaked data β€” purportedly, samples of Telus employee payroll data and source code β€” on a hacker site.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-44310 β€Ό

In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1029 β€Ό

The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.3. This is due to missing or incorrect nonce validation on the regenerateSitemaps function. This makes it possible for unauthenticated attackers to regenerate Sitemaps via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1030 β€Ό

A vulnerability has been found in SourceCodester Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of the argument un leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221755.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Tackling Software Supply Chain Issues With CNAPP πŸ•΄

The cloud-native application protection platform market is expanding as security teams look to protect their applications and the software supply chain.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-34248 β€Ό

SQL injection vulnerability in sourcecodester mobile-shop-system-php-mysql 1.0 allows remote attackers to log in via crafterdstring in the email field of the log in page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35290 β€Ό

File Upload vulnerability in balerocms-src 0.8.3 allows remote attackers to run arbitrary code via rich text editor on /admin/main/mod-blog page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24189 β€Ό

An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.

πŸ“– Read

via "National Vulnerability Database".