๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-30515 โ€ผ

Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30524 โ€ผ

Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30517 โ€ผ

Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30521 โ€ผ

A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30522 โ€ผ

A missing permission check in Jenkins Fogbugz Plugin 2.2.17 and earlier allows attackers with Item/Read permission to trigger builds of jobs specified in a 'jobname' request parameter.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30532 โ€ผ

A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresponding to the attacker-specified repository.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30513 โ€ผ

Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด FBI & FCC Warn on 'Juice Jacking' at Public Chargers, But What's the Risk? ๐Ÿ•ด

Hackers can compromise public charging hubs to steal data, install malware on phones, and more, threatening individuals and businesses alike.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด When Banking Laws Don't Protect Consumers From Cybertheft ๐Ÿ•ด

If attackers use your stolen login information or set up wire transfers, you might be out of luck.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Lazarus Group's 'DeathNote' Cluster Pivots to Defense Sector ๐Ÿ•ด

Usually focused on going after cryptocurrency organizations, the threat actor has begun targeting defense companies around the world.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด (ISC)ยฒ Certified in Cybersecurity Earns ANAB Accreditation to ISO 17024 and Surpasses 15,000 Certification Holders ๐Ÿ•ด

Entry-level cybersecurity certification is now accredited to the highest global standards alongside other globally recognized (ISC)ยฒ certifications like the CISSPยฎ

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-3404 โ€ผ

** REJECT ** This candidate is unused by its CNA.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1993 โ€ผ

LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26424 โ€ผ

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1992 โ€ผ

RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26408 โ€ผ

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26404 โ€ผ

Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐Ÿ“– Read

via "National Vulnerability Database".