๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-30528 โ€ผ

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30518 โ€ผ

A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30527 โ€ผ

Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30531 โ€ผ

Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30519 โ€ผ

A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30515 โ€ผ

Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30524 โ€ผ

Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30517 โ€ผ

Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30521 โ€ผ

A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30522 โ€ผ

A missing permission check in Jenkins Fogbugz Plugin 2.2.17 and earlier allows attackers with Item/Read permission to trigger builds of jobs specified in a 'jobname' request parameter.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30532 โ€ผ

A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresponding to the attacker-specified repository.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30513 โ€ผ

Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด FBI & FCC Warn on 'Juice Jacking' at Public Chargers, But What's the Risk? ๐Ÿ•ด

Hackers can compromise public charging hubs to steal data, install malware on phones, and more, threatening individuals and businesses alike.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด When Banking Laws Don't Protect Consumers From Cybertheft ๐Ÿ•ด

If attackers use your stolen login information or set up wire transfers, you might be out of luck.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Lazarus Group's 'DeathNote' Cluster Pivots to Defense Sector ๐Ÿ•ด

Usually focused on going after cryptocurrency organizations, the threat actor has begun targeting defense companies around the world.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด (ISC)ยฒ Certified in Cybersecurity Earns ANAB Accreditation to ISO 17024 and Surpasses 15,000 Certification Holders ๐Ÿ•ด

Entry-level cybersecurity certification is now accredited to the highest global standards alongside other globally recognized (ISC)ยฒ certifications like the CISSPยฎ

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-3404 โ€ผ

** REJECT ** This candidate is unused by its CNA.

๐Ÿ“– Read

via "National Vulnerability Database".