πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-25415 β€Ό

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24931 β€Ό

Windows Secure Channel Denial of Service Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26551 β€Ό

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22808 β€Ό

An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28808 β€Ό

Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28226 β€Ό

Windows Enroll Engine Security Feature Bypass Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28255 β€Ό

Windows DNS Server Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28301 β€Ό

Microsoft Edge (Chromium-based) Tampering Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28271 β€Ό

Windows Kernel Memory Information Disclosure Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28299 β€Ό

Visual Studio Spoofing Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28300 β€Ό

Azure Service Connector Security Feature Bypass Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28237 β€Ό

Windows Kernel Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28243 β€Ό

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23375 β€Ό

Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28311 β€Ό

Microsoft Word Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28228 β€Ό

Windows Spoofing Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Microsoft (& Apple) Patch Tuesday, April 2023 Edition β™ŸοΈ

Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, Apple has released a set of important updates addressing two zero-day vulnerabilities that are being used to attack iPhones, iPads and Macs.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2023-22613 β€Ό

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.

πŸ“– Read

via "National Vulnerability Database".
⚠ Attention gamers! Motherboard maker MSI admits to breach, issues β€œrogue firmware” alert ⚠

Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-48437 β€Ό

An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificate.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30512 β€Ό

CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.

πŸ“– Read

via "National Vulnerability Database".