πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-24130 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23004 β€Ό

In the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1097 β€Ό

Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated by a 3rd party analyst and have been confirmed exploitable special thanks to Lionel Musonza for the discovery.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24132 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey3_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23002 β€Ό

In the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Dish Blames Ransomware Attack for Disruptions of Internal Systems, Call Center Services πŸ•΄

The cyberattackers might have potentially accessed customer information, the service provider warns.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Forescout Addresses Modern SecOps Challenges With Launch of Forescout XDR πŸ•΄

New eXtended Detection and Response Solution is 450X more efficient than typical SOCs at converting telemetry and logs into actionable alerts.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Visibility Is as Vital as Zero Trust for Low-Code/No-Code Security πŸ•΄

By authenticating and authorizing every application, and by maintaining data lineage for auditing, enterprises can reduce the chances of data exfiltration.

πŸ“– Read

via "Dark Reading".
πŸ•΄ DoControl's 2023 SaaS Security Threat Landscape Report Finds Enterprises and Mid-Market Organizations Have Exposed Public SaaS Assets πŸ•΄

Volume of SaaS assets and events magnifies risks associated with manual management and remediation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-24127 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5026 β€Ό

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 193662.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24117 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepauth_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24126 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey4_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24120 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24125 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey2_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24124 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24121 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5001 β€Ό

IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24123 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".