πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-43923 β€Ό

IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0586 β€Ό

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor+ role to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep123: Crypto company compromise kerfuffle [Audio + Text] ⚠

Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

πŸ“– Read

via "Naked Security".
πŸ‘1πŸ€”1
β€Ό CVE-2023-0481 β€Ό

In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Evaluating the Cyber War Set Off by Russian Invasion of Ukraine πŸ•΄

Preparation and cooperation helped to mitigate the worst of the digital damage, amid cyber sorties from all sides.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Who’s Behind the Botnet-Based Service BHProxies? β™ŸοΈ

A security firm has discovered that a five-year-old crafty botnet known as Mylobot appears to be powering a residential proxy service called BHProxies, which offers paying customers the ability to route their web traffic anonymously through compromised computers. Here’s a closer look at Mylobot, and a deep dive into who may be responsible for operating the BHProxies service.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ 'New Class of Bugs' in Apple Devices Opens the Door to Complete Takeover πŸ•΄

With the right kind of exploit, there's hardly any function, app, or bit of data an attacker couldn't access on your Mac, iPad, or iPhone.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA: Beware of DDoS, Web Defacements on Anniversary of Russian Invasion of Ukraine πŸ•΄

The Cybersecurity and Infrastructure Security Agency advises US and European nations to prepare for possible website attacks marking the Feb. 24 invasion of Ukraine by Russia.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Canadian Telecom Firm Telus Reportedly Investigating Breach πŸ•΄

A threat actor has leaked data β€” purportedly, samples of Telus employee payroll data and source code β€” on a hacker site.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-44310 β€Ό

In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1029 β€Ό

The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.3. This is due to missing or incorrect nonce validation on the regenerateSitemaps function. This makes it possible for unauthenticated attackers to regenerate Sitemaps via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1030 β€Ό

A vulnerability has been found in SourceCodester Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of the argument un leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221755.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Tackling Software Supply Chain Issues With CNAPP πŸ•΄

The cloud-native application protection platform market is expanding as security teams look to protect their applications and the software supply chain.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-34248 β€Ό

SQL injection vulnerability in sourcecodester mobile-shop-system-php-mysql 1.0 allows remote attackers to log in via crafterdstring in the email field of the log in page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35290 β€Ό

File Upload vulnerability in balerocms-src 0.8.3 allows remote attackers to run arbitrary code via rich text editor on /admin/main/mod-blog page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24189 β€Ό

An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34249 β€Ό

SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-34167 β€Ό

Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ The UN's cyber crime treaty could be a privacy disaster πŸ“’

Although a UN committee is fleshing out a new international cyber crime treaty, experts question whether it’ll make any positive difference to businesses

πŸ“– Read

via "ITPro".
πŸ“’ LockBit leaks 44GB of Royal Mail's data, new Β£33m ransom set πŸ“’

200 employees are believed to be affected with vaccine records, salary information, HR formal dismissal documents, and business contract documents all appearing to be included in the leak

πŸ“– Read

via "ITPro".
πŸ‘3
β€Ό CVE-2023-1035 β€Ό

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been classified as critical. Affected is an unknown function of the file update_user.php. The manipulation of the argument user_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221784.

πŸ“– Read

via "National Vulnerability Database".