πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Adaptive Access Technologies Gaining Traction for Security, Agility πŸ•΄

With companies pushing to adopt Zero Trust frameworks, adaptive authentication and access β€” once languishing β€” looks finally ready to move out of the doldrums.

πŸ“– Read

via "Dark Reading".
πŸ“’ Okta launches new partner programme to capture $80b identity market πŸ“’

Revamped initiative introduces a new tiering system and badging model to showcase partner capabilities

πŸ“– Read

via "ITPro".
πŸ“’ 3CX CEO confirms supply chain malware attack πŸ“’

The VoIP company has confirmed that its desktop app has been infected with malware and urged customers to uninstall it until the new version is released

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ How Intel's FaceCatcher hopes to eradicate real-time deepfakes πŸ“’

The company’s β€˜blood flow’ breakthrough could banish deepfakes to history

πŸ“– Read

via "ITPro".
πŸ“’ Multi-cloud β€˜over-permissioning’ causing cyber risk headaches for businesses πŸ“’

With multi-cloud environments expanding, businesses are creating too many unused identities that can be abused

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft Security Copilot could be a seismic success for the tech industry πŸ“’

The tool has been greeted with overwhelming excitement from security professionals and stands to change the lives of threat analysts forever

πŸ“– Read

via "ITPro".
πŸ“’ Climb Channel Solutions bags UK double deal with Malwarebytes and Invicti πŸ“’

The speciality IT distributor’s UK&I portfolio now includes Invicti’s AppSec solutions and Malwarebytes’ full business offering

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-29140 β€Ό

An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28843 β€Ό

PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain privileges, modify data, and potentially affect system availability. The cause of this issue is that SQL queries were being constructed with user input which had not been properly filtered. Only deployments on PrestaShop 1.6 are affected. Users are advised to upgrade to module version 3.16.4. There are no known workarounds for this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27160 β€Ό

forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29137 β€Ό

An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadvertently returns the timezone preference for arbitrary users, which can be used to de-anonymize users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27159 β€Ό

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26925 β€Ό

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29141 β€Ό

An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29139 β€Ό

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissions makes many CheckUserLog API requests in some configurations, denial of service can occur (RequestTimeoutException or upstream request timeout).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23594 β€Ό

An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unauthenticated attackers with access to execute commands intended only for valid/authenticated users, such as file uploads and configuration changes.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Pro-Islam 'Anonymous Sudan' Hacktivists Likely a Front for Russia's Killnet Operation πŸ•΄

"Anonymous Sudan" has been claiming that its DDoS attacks are in retaliation for anti-Islamic activities, but at least one security vendor is suspicious about its true motives.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Mimecast Report Reveals Nearly 60% of Companies in UAE and Saudi Arabia Need to Increase Cybersecurity Spending πŸ•΄

The State of Email Security Report reveals cyber risk commands the C-suite's focus.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Elastic Expands Cloud Security Capabilities for AWS πŸ•΄

Launching CSPM, container workload security, and cloud vulnerability management to modernize cloud security operations.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The FDA's Medical Device Cybersecurity Overhaul Has Real Teeth, Experts Say πŸ•΄

The physical and cyber safety issues surrounding medical devices like IV pumps is finally being meaningfully addressed by a new policy taking effect this week.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-26858 β€Ό

SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.

πŸ“– Read

via "National Vulnerability Database".