πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-1712 β€Ό

Use of Hard-coded, Security-relevant Constants in GitHub repository deepset-ai/haystack prior to 0.1.30.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28935 β€Ό

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA, an authenticated user that has the permissions to modify core entities can cause command execution as the system user that runs the web process. As the "Distributed UIMA Cluster Computing" module for UIMA is retired, we do not plan to release a fix for this issue. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1699 β€Ό

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-28733 β€Ό

AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28731 β€Ό

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28732 β€Ό

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system files via path traversal, when being granted access to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin in versions below 8.3.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23681 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25040 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vova Anokhin WordPress Shortcodes Plugin Ò€” Shortcodes Ultimate plugin <= 5.12.6 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24399 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Stop Blaming the End User for Security Risk πŸ•΄

Don't count on securing end users for system security. Instead, focus on better securing the systems β€” make them closed by default and build with a security-first approach.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep128: So you want to be a cybercriminal? [Audio + Text] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-25076 β€Ό

A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba). A specially crafted HTTP, TLS or DTLS packet can lead to arbitrary code execution. An attacker could send a malicious packet to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1725 β€Ό

Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows Server Side Request Forgery.This issue affects Project Management System: before 4.09.31.125.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Socura Launches Managed SASE (MSASE) Service πŸ•΄

SASE reduces security & connectivity costs and improves employee experience.

πŸ“– Read

via "Dark Reading".
⚠ Supply chain blunder puts 3CX telephone app users at risk ⚠

Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.

πŸ“– Read

via "Naked Security".
πŸ•΄ DataDome Closes $42M in Series C Funding to Advance the Fight Against Bot-Driven Cyberattacks and Fraud πŸ•΄

The investment will fund global commercial rollout and R&D efforts to debilitate fraudsters.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-29059 β€Ό

3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the Electron macOS application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24473 β€Ό

An information disclosure vulnerability exists in the TGAInput::read_tga2_header functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Organizations Reassess Cyber Insurance as Self-Insurance Strategies Emerge πŸ•΄

Risk reassessment is shaking up the cybersecurity insurance market, leading some organizations to consider their options, including self-insurance.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-24472 β€Ό

A denial of service vulnerability exists in the FitsOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide malicious input to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30350 β€Ό

Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader.

πŸ“– Read

via "National Vulnerability Database".