πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ›  I2P 2.2.0 πŸ› 

I2P is an anonymizing network, offering a simple layer that identity-sensitive applications can use to securely communicate. All data is wrapped with several layers of encryption, and the network is both distributed and dynamic, with no trusted parties. This is the source code release version.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Deepfakes, Synthetic Media: How Digital Propaganda Undermines Trust πŸ•΄

Organizations must educate themselves and their users on how to detect, disrupt, and defend against the increasing volume of online disinformation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-27074 β€Ό

BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1299 β€Ό

HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1396 β€Ό

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin/traveller_details.php. The manipulation of the argument address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222983.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1395 β€Ό

A vulnerability was found in SourceCodester Yoga Class Registration System 1.0. It has been declared as problematic. This vulnerability affects the function query of the file admin/user/list.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-222982 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1397 β€Ό

A vulnerability classified as problematic has been found in SourceCodester Online Student Management System 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument adminname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222984.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24180 β€Ό

Libelfin v0.3 was discovered to contain an integer overflow in the load function at elf/mmap_loader.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted elf file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27073 β€Ό

A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1394 β€Ό

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been classified as critical. This affects the function mysqli_query of the file bsitemp.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222981 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46743 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1296 β€Ό

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workloadÒ€ℒs variables. Fixed in 1.4.6 and 1.5.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1398 β€Ό

A vulnerability classified as critical was found in XiaoBingBy TeaCMS 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/upload. The manipulation leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222985 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1391 β€Ό

A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222978 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1392 β€Ό

A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is the function save_menu. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222979.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Businesses Can Get Ready for AI-Powered Security Threats πŸ•΄

Organizations need to take steps now to strengthen their cyber defenses.

πŸ“– Read

via "Dark Reading".
⚠ Firefox 111 patches 11 holes, but not 1 zero-day among them… ⚠

In the game of cricket, 111 is an unauspicious number, but for Firefox, there doesn't seem to be much to worry about this month.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-23388 β€Ό

Windows Bluetooth Driver Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21708 β€Ό

Remote Procedure Call Runtime Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23398 β€Ό

Microsoft Excel Spoofing Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23421 β€Ό

Windows Kernel Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".