🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Pro-Islam 'Anonymous Sudan' Hacktivists Likely a Front for Russia's Killnet Operation 🕴

"Anonymous Sudan" has been claiming that its DDoS attacks are in retaliation for anti-Islamic activities, but at least one security vendor is suspicious about its true motives.

📖 Read

via "Dark Reading".
🕴 Mimecast Report Reveals Nearly 60% of Companies in UAE and Saudi Arabia Need to Increase Cybersecurity Spending 🕴

The State of Email Security Report reveals cyber risk commands the C-suite's focus.

📖 Read

via "Dark Reading".
🕴 Elastic Expands Cloud Security Capabilities for AWS 🕴

Launching CSPM, container workload security, and cloud vulnerability management to modernize cloud security operations.

📖 Read

via "Dark Reading".
🕴 The FDA's Medical Device Cybersecurity Overhaul Has Real Teeth, Experts Say 🕴

The physical and cyber safety issues surrounding medical devices like IV pumps is finally being meaningfully addressed by a new policy taking effect this week.

📖 Read

via "Dark Reading".
‼ CVE-2023-26858 ‼

SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-1785 ‼

A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-224700.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-27162 ‼

openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-4899 ‼

A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-27163 ‼

request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-1784 ‼

A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224699.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0208 ‼

NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buffer overflow through the bound socket. A successful exploit of this vulnerability may lead to denial of service and data tampering.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-1789 ‼

Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0189 ‼

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0195 ‼

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of the driver

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0188 ‼

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged user can cause improper restriction of operations within the bounds of a memory buffer cause an out-of-bounds read, which may lead to denial of service.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0187 ‼

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read can lead to denial of service.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0182 ‼

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service, information disclosure, and data tampering.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0192 ‼

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to escalation of privileges and information disclosure.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0197 ‼

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0185 ‼

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign conversion issuescasting an unsigned primitive to signed may lead to denial of service or information disclosure.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0194 ‼

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer driver, where an invalid display configuration may lead to denial of service.

📖 Read

via "National Vulnerability Database".