πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-45064 β€Ό

The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resource with specific content-type and control the include path (i.e. writing content). The impact of a successful attack is privilege escalation to administrative power. Please update to Apache Sling Engine >= 2.14.0 and enable the "Check Content-Type overrides" configuration option.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Google Tackles Open Source Security With New Dependency Service πŸ•΄

With deps.dev API and Assured OSS, Google is addressing the common challenges software developers face in securing the software supply chain.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How to Define Tier-Zero Assets in Active Directory Security πŸ•΄

There are plenty of AD objects and groups that should be considered tier zero in every environment, but some will vary among organizations.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-45358 β€Ό

Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <=Γ‚ 1.4.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2021 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44625 β€Ό

Auth. (admin+) Stored Cross-Site Scripting') vulnerability in Zephilou Cyklodev WP Notify plugin <=Γ‚ 1.2.1 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ The 'cyber aSaaSin' manual πŸ“’

Providing valuable insights to identify SaaS data enemies and win the battle against SaaS data threats

πŸ“– Read

via "ITPro".
πŸ”₯1
πŸ“’ The complete SaaS backup buyer's guide πŸ“’

Informing you about the realities of SaaS data protection and why an SaaS back up is essential

πŸ“– Read

via "ITPro".
πŸ•΄ Legion Malware Marches onto Web Servers to Steal Credentials, Spam Mobile Users πŸ•΄

A novel credential harvester compromises SMTP services to steal data from a range of hosted services and providers, and can also launch SMS-based spam attacks against devices using US mobile carriers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Majority of US IT Pros Told to Keep Quiet About Data Breaches πŸ•΄

To report or not report? While more than half of all companies have suffered a data breach, 71% of IT professionals say they have been told to not report an incident, which could mean legal jeopardy.

πŸ“– Read

via "Dark Reading".
πŸ›  Wireshark Analyzer 4.0.5 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
πŸ›  Faraday 4.3.5 πŸ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

πŸ“– Read

via "Packet Storm Security".
πŸ“’ Best practices for Microsoft 365 business continuity πŸ“’

Discover how to mitigate the effects of large-scale, high-cost data loss disasters

πŸ“– Read

via "ITPro".
⚠ Patch Tuesday: Microsoft fixes a zero-day, and two curious bugs that take the Secure out of Secure Boot ⚠

Is Secure Boot without the Secure just "Boot"?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-29597 β€Ό

bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29598 β€Ό

lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27812 β€Ό

bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Internet Reform Trilemma πŸ•΄

An "open" Internet faces challenges from autocratic governance models. Policymakers should instead think about creating an Internet that's equitable, inclusive, and secure.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep130: Open the garage bay doors, HAL [Audio + Text] ⚠

I'm sorry, Dave. I'm afraid I can't... errr, no, hang on a minute, I can do that easily! Worldwide! Right now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-27779 β€Ό

AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30630 β€Ό

Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.

πŸ“– Read

via "National Vulnerability Database".