πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-23002 β€Ό

In the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Dish Blames Ransomware Attack for Disruptions of Internal Systems, Call Center Services πŸ•΄

The cyberattackers might have potentially accessed customer information, the service provider warns.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Forescout Addresses Modern SecOps Challenges With Launch of Forescout XDR πŸ•΄

New eXtended Detection and Response Solution is 450X more efficient than typical SOCs at converting telemetry and logs into actionable alerts.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Visibility Is as Vital as Zero Trust for Low-Code/No-Code Security πŸ•΄

By authenticating and authorizing every application, and by maintaining data lineage for auditing, enterprises can reduce the chances of data exfiltration.

πŸ“– Read

via "Dark Reading".
πŸ•΄ DoControl's 2023 SaaS Security Threat Landscape Report Finds Enterprises and Mid-Market Organizations Have Exposed Public SaaS Assets πŸ•΄

Volume of SaaS assets and events magnifies risks associated with manual management and remediation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-24127 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5026 β€Ό

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 193662.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24117 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepauth_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24126 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey4_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24120 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24125 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey2_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24124 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24121 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5001 β€Ό

IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24123 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22738 β€Ό

vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. It may lead to unintended access: if a user from organization A is accidentally assigned to organization B, they will retain their permissions and therefore might be able to access stuff they should not be allowed to access. This issue is patched in version 3.8.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24118 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24122 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the ssid_5g parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24119 β€Ό

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet.

πŸ“– Read

via "National Vulnerability Database".