๐ด Polish Politician's Phone Patrolled by Pegasus ๐ด
๐ Read
via "Dark Reading".
A mayor backing Polish opposition elections in parliament has been targeted by special services with Pegasus spyware.๐ Read
via "Dark Reading".
Dark Reading
Polish Politician's Phone Patrolled by Pegasus
A mayor backing Polish opposition elections in parliament has been targeted by special services with Pegasus spyware.
๐ด Indigo Books Refuses LockBit Ransomware Demand ๐ด
๐ Read
via "Dark Reading".
Canada's largest bookseller rejected the pressure of the ransomware gang's countdown timer, despite data threats.๐ Read
via "Dark Reading".
Dark Reading
Indigo Books Refuses LockBit Ransomware Demand
Canada's largest bookseller rejected the pressure of the ransomware gang's countdown timer, despite data threats.
๐ด EV Charging Infrastructure Offers an Electric Cyberattack Opportunity ๐ด
๐ Read
via "Dark Reading".
Attackers have already targeted electric vehicle (EV) charging stations, and experts are calling for cybersecurity standards to protect this necessary component of the electrified future.๐ Read
via "Dark Reading".
Dark Reading
EV Charging Infrastructure Offers an Electric Cyberattack Opportunity
Attackers have already targeted electric vehicle (EV) charging stations, and experts are calling for cybersecurity standards to protect this necessary component of the electrified future.
โผ CVE-2023-27561 โผ
๐ Read
via "National Vulnerability Database".
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.๐ Read
via "National Vulnerability Database".
๐1
โผ CVE-2023-24643 โผ
๐ Read
via "National Vulnerability Database".
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-27566 โผ
๐ Read
via "National Vulnerability Database".
Cubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds write via a crafted Section Offset Table or Count Info Table in an MOC3 file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24641 โผ
๐ Read
via "National Vulnerability Database".
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24642 โผ
๐ Read
via "National Vulnerability Database".
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26492 โผ
๐ Read
via "National Vulnerability Database".
Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side Request Forgery (SSRF) when importing a file from a remote web server (POST to `/files/import`). An attacker can bypass the security controls by performing a DNS rebinding attack and view sensitive data from internal servers or perform a local port scan. An attacker can exploit this vulnerability to access highly sensitive internal server(s) and steal sensitive information. This issue was fixed in version 9.23.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46973 โผ
๐ Read
via "National Vulnerability Database".
Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23927 โผ
๐ Read
via "National Vulnerability Database".
Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been fixed in version 4.3.7.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-27567 โผ
๐ Read
via "National Vulnerability Database".
In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-0968 โผ
๐ Read
via "National Vulnerability Database".
The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the รขโฌหdnรขโฌโข, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26488 โผ
๐ Read
via "National Vulnerability Database".
OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent transfers from the receiver of that token may overflow the balance as reported by `balanceOf`. The issue exclusively presents with batches of size 1. The issue has been patched in 4.8.2.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-27574 โผ
๐ Read
via "National Vulnerability Database".
ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENTITLEMENTS.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23313 โผ
๐ Read
via "National Vulnerability Database".
Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927 v4.4.2.2; and Vigor2915, Vigor2765, Vigor2766, Vigor2135 v4.4.2.0; Vigor2763 v4.4.2.1; Vigor2862 and Vigor2926 v3.9.9.0; Vigor2925 v3.9.3; Vigor2952 and Vigor3220 v3.9.7.3; Vigor2133 and Vigor2762 v3.9.6.4; and Vigor2832 v3.9.6.2.๐ Read
via "National Vulnerability Database".
๐ฅ1
โผ CVE-2023-26213 โผ
๐ Read
via "National Vulnerability Database".
On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters.๐ Read
via "National Vulnerability Database".
๐ด Rapid7 Brings Threat Intel Data to USF Cybersecurity Lab ๐ด
๐ Read
via "Dark Reading".
The Rapid7 Cyber Threat Intelligence Laboratory at the University of South Florida will provide data on real-world threats for faculty and students to use in their research.๐ Read
via "Dark Reading".
Dark Reading
Rapid7 Brings Threat Intel Data to USF Cybersecurity Lab
The Rapid7 Cyber Threat Intelligence Laboratory at the University of South Florida will provide data on real-world threats for faculty and students to use in their research.
โผ CVE-2023-26047 โผ
๐ Read
via "National Vulnerability Database".
teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack when a specific case-sensitive hex entities payload with special characters such as CR/LF and horizontal tab is used. This vulnerability allows an attacker to execute arbitrary JavaScript code on the victim's browser and compromise the security of the web application. An attacker can exploit this vulnerability to bypass common web attack threat rules in teler-waf and launch cross-site scripting (XSS) attacks. The attacker can execute arbitrary JavaScript code on the victim's browser and steal sensitive information, such as login credentials and session tokens, or take control of the victim's browser and perform malicious actions. This issue has been patched in version 0.2.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-27290 โผ
๐ Read
via "National Vulnerability Database".
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1170 โผ
๐ Read
via "National Vulnerability Database".
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.๐ Read
via "National Vulnerability Database".