πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-28237 β€Ό

Windows Kernel Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28243 β€Ό

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23375 β€Ό

Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28311 β€Ό

Microsoft Word Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28228 β€Ό

Windows Spoofing Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Microsoft (& Apple) Patch Tuesday, April 2023 Edition β™ŸοΈ

Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, Apple has released a set of important updates addressing two zero-day vulnerabilities that are being used to attack iPhones, iPads and Macs.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2023-22613 β€Ό

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.

πŸ“– Read

via "National Vulnerability Database".
⚠ Attention gamers! Motherboard maker MSI admits to breach, issues β€œrogue firmware” alert ⚠

Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-48437 β€Ό

An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificate.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30512 β€Ό

CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ CrowdStrike Expands Falcon to Include IoT πŸ•΄

CrowdStrike Falcon Insight for IoT covers Internet of Things, Industrial IoT, Operations Technology, as well as medical devices.

πŸ“– Read

via "Dark Reading".
πŸ“’ OpenAI to pay up to $20k in rewards through new bug bounty program πŸ“’

The move follows a period of unrest over data security concerns

πŸ“– Read

via "ITPro".
⚠ Microsoft fixes a zero-day – and two curious bugs that take the Secure out of Secure Boot ⚠

Is Secure Boot without the Secure just "Boot"?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-29580 β€Ό

yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27826 β€Ό

SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47053 β€Ό

An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1829 β€Ό

A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation.Γ‚ The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure.Γ‚ A local attacker user can use this vulnerability to elevate its privileges to root. We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22616 β€Ό

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an attacker can corrupt SMRAM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24350 β€Ό

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. Specially formatted buffer contents used for software SMI could cause SMRAM corruption, leading to escalation of privilege.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29574 β€Ό

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27216 β€Ό

An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.

πŸ“– Read

via "National Vulnerability Database".