πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ WooCommerce Payments plugin for WordPress has an admin-level hole – patch now! ⚠

Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-36691 β€Ό

An issue was discovered in the Linux kernel before 5.8. lib/nlattr.c allows attackers to cause a denial of service (unbounded recursion) via a nested Netlink policy with a back reference.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3844 β€Ό

Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated credential leak, that user account's current session is still valid after the password change, potentially allowing the attacker who originally compromised the credential to remain logged in and able to cause further damage. This vulnerability is mitigated by the use of the Platform Login feature. This issue is related to CVE-2019-5638.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28152 β€Ό

An issue was discovered in Independentsoft JWord before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47502 β€Ό

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38745 β€Ό

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Malicious ChatGPT Extensions Add to Google Chrome Woes πŸ•΄

The second malicious ChatGPT extension for Chrome has been discovered, giving malicious actors access to users' Facebook accounts through stolen cookies.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zoom Zoom: 'Dark Power' Ransomware Extorts 10 Targets in Less Than a Month πŸ•΄

A new threat actor is racking up victims and showing unusual agility. Part of its success could spring from the use of the Nim programming language.

πŸ“– Read

via "Dark Reading".
πŸ•΄ GitHub's Private RSA SSH Key Mistakenly Exposed in Public Repository πŸ•΄

GitHub hastens to replace its RSA SSH host key after an exposure mishap threatens users with man-in-the-middle attacks and organization impersonation.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CyberSecure Announces Strategic Alliance πŸ•΄

The joint partnership represents expanded market opportunities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Tesla Model 3 Hacked in Less Than 2 Minutes at Pwn2Own Contest πŸ•΄

In two days, ethical researchers from 10 countries have unearthed more than 22 zero-day bugs in a wide range of technologies at the annual hacking contest.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-20995 β€Ό

In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-241910279

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21041 β€Ό

In append_to_params of param_util.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-250123688References: N/A

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21043 β€Ό

In (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239872581References: N/A

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21036 β€Ό

In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21042 β€Ό

In (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239873326References: N/A

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21026 β€Ό

In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-254681548

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21030 β€Ό

In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226234140

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21000 β€Ό

In MediaCodec.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-194783918

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21076 β€Ό

In createTransmitFollowupRequest of nan.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-261857623References: N/A

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21078 β€Ό

In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-254840211References: N/A

πŸ“– Read

via "National Vulnerability Database".