โผ CVE-2023-30515 โผ
๐ Read
via "National Vulnerability Database".
Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30524 โผ
๐ Read
via "National Vulnerability Database".
Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30517 โผ
๐ Read
via "National Vulnerability Database".
Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30521 โผ
๐ Read
via "National Vulnerability Database".
A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30522 โผ
๐ Read
via "National Vulnerability Database".
A missing permission check in Jenkins Fogbugz Plugin 2.2.17 and earlier allows attackers with Item/Read permission to trigger builds of jobs specified in a 'jobname' request parameter.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30532 โผ
๐ Read
via "National Vulnerability Database".
A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresponding to the attacker-specified repository.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30513 โผ
๐ Read
via "National Vulnerability Database".
Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.๐ Read
via "National Vulnerability Database".
๐ด FBI & FCC Warn on 'Juice Jacking' at Public Chargers, But What's the Risk? ๐ด
๐ Read
via "Dark Reading".
Hackers can compromise public charging hubs to steal data, install malware on phones, and more, threatening individuals and businesses alike.๐ Read
via "Dark Reading".
Dark Reading
FBI & FCC Warn on 'Juice Jacking' at Public Chargers, but What's the Risk?
Hackers can compromise public charging hubs to steal data, install malware on phones, and more, threatening individuals and businesses alike.
๐ด When Banking Laws Don't Protect Consumers From Cybertheft ๐ด
๐ Read
via "Dark Reading".
If attackers use your stolen login information or set up wire transfers, you might be out of luck.๐ Read
via "Dark Reading".
Dark Reading
When Banking Laws Don't Protect Consumers From Cybertheft
If attackers use your stolen login information or set up wire transfers, you might be out of luck.
๐ด Lazarus Group's 'DeathNote' Cluster Pivots to Defense Sector ๐ด
๐ Read
via "Dark Reading".
Usually focused on going after cryptocurrency organizations, the threat actor has begun targeting defense companies around the world.๐ Read
via "Dark Reading".
Dark Reading
Lazarus Group's 'DeathNote' Cluster Pivots to Defense Sector
Usually focused on going after cryptocurrency organizations, the threat actor has begun targeting defense companies around the world.
๐ด Menlo Security Illustrates Importance of Browser Security as 4 in 5 Ransomware Attacks Include Threats Beyond Data Encryption ๐ด
๐ Read
via "Dark Reading".
๐ Read
via "Dark Reading".
Dark Reading
Menlo Security Illustrates Importance of Browser Security as 4 in 5 Ransomware Attacks Include Threats Beyond Data Encryption
MOUNTAIN VIEW, Calif., April 11, 2023 โ Menlo Security, a leader in browser security, today shared results from the CyberEdge Groupโs 10th Annual Cyberthreat Defense Report (CDR). This yearโs report, sponsored in part by Menlo Security, highlights the growingโฆ
๐ด (ISC)ยฒ Certified in Cybersecurity Earns ANAB Accreditation to ISO 17024 and Surpasses 15,000 Certification Holders ๐ด
๐ Read
via "Dark Reading".
Entry-level cybersecurity certification is now accredited to the highest global standards alongside other globally recognized (ISC)ยฒ certifications like the CISSPยฎ๐ Read
via "Dark Reading".
Dark Reading
(ISC)ยฒ Certified in Cybersecurity Earns ANAB Accreditation to ISO 17024 and Surpasses 15,000 Certification Holders
Entry-level cybersecurity certification is now accredited to the highest global standards alongside other globally recognized (ISC)ยฒ certifications like the CISSPยฎ
๐ด VulnCheck Named CVE Numbering Authority for Common Vulnerabilities and Exposures ๐ด
๐ Read
via "Dark Reading".
๐ Read
via "Dark Reading".
Dark Reading
VulnCheck Named CVE Numbering Authority for Common Vulnerabilities and Exposures
LEXINGTON, Mass.--(BUSINESS WIRE)--VulnCheck, the vulnerability intelligence company, today announced it has been authorized by the CVE Program as a CVE Numbering Authority (CNA). The company also announced the launch of VulnCheck Advisories, a program designedโฆ
๐ด Report Reveals ChatGPT Already Involved in Data Leaks, Phishing Scams & Malware Infections ๐ด
๐ Read
via "Dark Reading".
๐ Read
via "Dark Reading".
Dark Reading
Report Reveals ChatGPT Already Involved in Data Leaks, Phishing Scams & Malware Infections
MIAMI, April 12, 2023 /PRNewswire/ -- Network Assured has reported that data leaks, phishing scams and malware infections attributable to ChatGPT are on the rise. The report tracks the most significant cybersecurity breaches in which ChatGPT has been involvedโฆ
โผ CVE-2022-3404 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** This candidate is unused by its CNA.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1993 โผ
๐ Read
via "National Vulnerability Database".
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26424 โผ
๐ Read
via "National Vulnerability Database".
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1992 โผ
๐ Read
via "National Vulnerability Database".
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26408 โผ
๐ Read
via "National Vulnerability Database".
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26404 โผ
๐ Read
via "National Vulnerability Database".
Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.๐ Read
via "National Vulnerability Database".