πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ How Password Managers Can Get Hacked πŸ•΄

Password managers aren't foolproof, but they do help mitigate risks from weak credentials and password reuse. Following best practices can contribute to a company's defenses.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How CIEM Can Improve Identity, Permissions Management for Multicloud Deployments πŸ•΄

The gap between permissions granted and permissions used exposes organizations to increased risk. (Part two of a two-part series.)

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-26917 β€Ό

libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_mem.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47464 β€Ό

In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47338 β€Ό

In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-47467 β€Ό

In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47337 β€Ό

In media service, there is a missing permission check. This could lead to local denial of service in media service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47468 β€Ό

In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47465 β€Ό

In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27645 β€Ό

An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47362 β€Ό

In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47466 β€Ό

In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-47463 β€Ό

In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47336 β€Ό

In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47335 β€Ό

In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27179 β€Ό

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Attackers Hide RedLine Stealer Behind ChatGPT, Google Bard Facebook Ads πŸ•΄

The campaign shrouds the commodity infostealer in OpenAI files in a play that aims to take advantage of the growing public interest in AI-based chatbots.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-0645 β€Ό

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commitΓ‚  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23277 β€Ό

Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML from the "Snippet code" form field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28062 β€Ό

Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended access restrictions and perform unauthorized actions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27192 β€Ό

An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe_net_check_url, KEY_Cirus_scan_whitelist and KEY_AD_NEW_USER_AVOID_TIME parameters.

πŸ“– Read

via "National Vulnerability Database".