πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-28654 β€Ό

Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation of the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28375 β€Ό

Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26346 β€Ό

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ What is cloud ransomware and how can you avoid attacks? πŸ“’

With ransomware increasingly targeting cloud applications and data, as well as cloud-based companies, we explain how you can protect your business

πŸ“– Read

via "ITPro".
πŸ“’ Organisations could soon be using generative AI to prevent phishing attacks πŸ“’

Training an AI to learn a CEO's writing style could prevent the next big cyber attack

πŸ“– Read

via "ITPro".
πŸ“’ AdRem NetCrunch 13 review: Great network monitoring for time-poor SMBs πŸ“’

Easily deployed and affordable network monitoring for SMBs with a range of highly informative viewpoints

πŸ“– Read

via "ITPro".
πŸ“’ Latitude Financial's data policies questioned after more than 14 million records stolen πŸ“’

Some of the data is from at least 2005 and includes customers’ name, address, and date of birth

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft set to block emails from unsupported Exchange servers πŸ“’

The tech giants described emails coming from these servers as β€œpersistently vulnerable” and is aiming to encourage admins to secure their environments

πŸ“– Read

via "ITPro".
πŸ“’ UK snares "several thousand" potential hackers in DDoS-for-hire honeypot πŸ“’

The sting follows a recent crackdown on DDoS-for-hire services globally

πŸ“– Read

via "ITPro".
πŸ“’ Ex-NCSC CEO on the next big ransomware threat πŸ“’

Despite a devastating few years for cyber security, the former NCSC CEO Ciaran Martin is confident that businesses have learned critical lessons

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-45460 β€Ό

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the web server, resulting in a system reboot. An unauthenticated and remote attacker can execute arbitrary code by sending a crafted HTTP request that triggers the overflow condition via a long URI passed to a sprintf call. NOTE: this is different than CVE-2018-10088, but this may overlap CVE-2017-16725.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1679 β€Ό

A vulnerability classified as critical was found in DriverGenius 9.70.0.346. This vulnerability affects the function 0x9C406104/0x9C40A108 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224236.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1678 β€Ό

A vulnerability classified as critical has been found in DriverGenius 9.70.0.346. This affects the function 0x9C40A0D8/0x9C40A0DC/0x9C40A0E0 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224235.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27229 β€Ό

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27232 β€Ό

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27231 β€Ό

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46397 β€Ό

FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable IV with CBC Mode.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1677 β€Ό

A vulnerability was found in DriverGenius 9.70.0.346. It has been rated as problematic. Affected by this issue is the function 0x9c40a0c8/0x9c40a0dc/0x9c40a0e0/0x9c40a0d8/0x9c4060d4/0x9c402004/0x9c402088/0x9c40208c/0x9c4060d0/0x9c4060cc/0x9c4060c4/0x9c402084 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-224234 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1681 β€Ό

A vulnerability, which was classified as problematic, was found in Xunrui CMS 4.61. Affected is an unknown function of the file /config/myfield/test.php. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-224238 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Does Data Literacy Enhance Data Security? πŸ•΄

With the rise in cloud-based security concerns and other issues, organizations must improve data literacy across the enterprise.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-1683 β€Ό

A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/Fcms/View/system_log.html. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224240.

πŸ“– Read

via "National Vulnerability Database".
❀1