๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ“ข How Intel's FaceCatcher hopes to eradicate real-time deepfakes ๐Ÿ“ข

The companyโ€™s โ€˜blood flowโ€™ breakthrough could banish deepfakes to history

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Multi-cloud โ€˜over-permissioningโ€™ causing cyber risk headaches for businesses ๐Ÿ“ข

With multi-cloud environments expanding, businesses are creating too many unused identities that can be abused

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Microsoft Security Copilot could be a seismic success for the tech industry ๐Ÿ“ข

The tool has been greeted with overwhelming excitement from security professionals and stands to change the lives of threat analysts forever

๐Ÿ“– Read

via "ITPro".
๐Ÿ“ข Climb Channel Solutions bags UK double deal with Malwarebytes and Invicti ๐Ÿ“ข

The speciality IT distributorโ€™s UK&I portfolio now includes Invictiโ€™s AppSec solutions and Malwarebytesโ€™ full business offering

๐Ÿ“– Read

via "ITPro".
โ€ผ CVE-2023-29140 โ€ผ

An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-28843 โ€ผ

PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain privileges, modify data, and potentially affect system availability. The cause of this issue is that SQL queries were being constructed with user input which had not been properly filtered. Only deployments on PrestaShop 1.6 are affected. Users are advised to upgrade to module version 3.16.4. There are no known workarounds for this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-27160 โ€ผ

forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-29137 โ€ผ

An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadvertently returns the timezone preference for arbitrary users, which can be used to de-anonymize users.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-27159 โ€ผ

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26925 โ€ผ

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-29141 โ€ผ

An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-29139 โ€ผ

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissions makes many CheckUserLog API requests in some configurations, denial of service can occur (RequestTimeoutException or upstream request timeout).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-23594 โ€ผ

An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unauthenticated attackers with access to execute commands intended only for valid/authenticated users, such as file uploads and configuration changes.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Pro-Islam 'Anonymous Sudan' Hacktivists Likely a Front for Russia's Killnet Operation ๐Ÿ•ด

"Anonymous Sudan" has been claiming that its DDoS attacks are in retaliation for anti-Islamic activities, but at least one security vendor is suspicious about its true motives.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Mimecast Report Reveals Nearly 60% of Companies in UAE and Saudi Arabia Need to Increase Cybersecurity Spending ๐Ÿ•ด

The State of Email Security Report reveals cyber risk commands the C-suite's focus.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Elastic Expands Cloud Security Capabilities for AWS ๐Ÿ•ด

Launching CSPM, container workload security, and cloud vulnerability management to modernize cloud security operations.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด The FDA's Medical Device Cybersecurity Overhaul Has Real Teeth, Experts Say ๐Ÿ•ด

The physical and cyber safety issues surrounding medical devices like IV pumps is finally being meaningfully addressed by a new policy taking effect this week.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-26858 โ€ผ

SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1785 โ€ผ

A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-224700.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-27162 โ€ผ

openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-4899 โ€ผ

A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

๐Ÿ“– Read

via "National Vulnerability Database".