πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-26056 β€Ό

XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, provided the target user does not have programming right. The problem has been patched in XWiki 14.8-rc-1, 14.4.5, and 13.10.10. There are no known workarounds for this issue.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ BlackLotus Bookit Found Targeting Windows 11 πŸ•΄

Sold for around $5,000 in hacking forums, the BlackLotus UEFI bootkit is capable of targeting even updated systems, researchers find.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Biden's Cybersecurity Strategy Calls for Software Liability, Tighter Critical Infrastructure Security πŸ•΄

The new White House plan outlines proposed minimum security requirements in critical infrastructure β€” and for shifting liability for software products to vendors.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA, MITRE Look to Take ATT&CK Framework Out of the Weeds πŸ•΄

The Decider tool is designed to make the ATT&CK framework more accessible and usable for security analysts of every level, with an intuitive interface and simplified language.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-1101 β€Ό

SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22381 β€Ό

A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability, an attacker would need existing permission to control the value of environment variables for use with GitHub Actions. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.8.0 and was fixed in versions 3.4.15, 3.5.12, 3.6.8, 3.7.5. This vulnerability was reported via the GitHub Bug Bounty program.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0656 β€Ό

A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35645 β€Ό

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230958.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46501 β€Ό

Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40633 β€Ό

A malicious actor can clone access cards used to open control cabinets secured with Rittal CMC III locks.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Highlights from the New U.S. Cybersecurity Strategy β™ŸοΈ

The Biden administration today issued its vision for beefing up the nation's collective cybersecurity posture, including calls for legislation establishing liability for software products and services that are sold with little regard for security. The White House's new national cybersecurity strategy also envisions a more active role by cloud providers and the U.S. military in disrupting cybercriminal infrastructure, and names China as the single biggest cyber threat to U.S. interests.

πŸ“– Read

via "Krebs on Security".
πŸ”₯1
πŸ•΄ IBM Contributes Supply Chain Security Tools to OWASP πŸ•΄

License Scanner and SBOM Utility will boost the capabilities of OWASP's CycloneDX Software Bill of Materials standard.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-1160 β€Ό

Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0457 β€Ό

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U(C) CPU modules all models all versions, FX5UJ CPU modules all models all versions, FX5S CPU modules all models all versions, FX5-ENET all versions and FX5-ENET/IP all versions allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ CISA: Tech industry 'shouldn't tolerate' Patch Tuesday πŸ“’

CISA director Jen Easterly said the tech industry has allowed the widespread acceptance of "deviant behaviours" to make a mockery of cyber security

πŸ“– Read

via "ITPro".
πŸ“’ Uncovering the ransomware threat from global supply chains πŸ“’

Everything is connected

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ Leaked today, exploited for life πŸ“’

How social media biometric patterns affect your future

πŸ“– Read

via "ITPro".
πŸ“’ The near and far future of ransomware business models πŸ“’

What would make ransomware actors change their criminal business models?

πŸ“– Read

via "ITPro".
πŸ“’ Trend Micro security predictions for 2023 πŸ“’

Prioritise cyber security strategies on capabilities rather than costs

πŸ“– Read

via "ITPro".
πŸ“’ Bitdefender releases free MortalKombat ransomware decryptor tool πŸ“’

While still a relatively new strain, MortalKombat has been used extensively to target users and steal cryptocurrency

πŸ“– Read

via "ITPro".