πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Best practices for Microsoft 365 business continuity πŸ“’

Discover how to mitigate the effects of large-scale, high-cost data loss disasters

πŸ“– Read

via "ITPro".
⚠ Patch Tuesday: Microsoft fixes a zero-day, and two curious bugs that take the Secure out of Secure Boot ⚠

Is Secure Boot without the Secure just "Boot"?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-29597 β€Ό

bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29598 β€Ό

lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27812 β€Ό

bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Internet Reform Trilemma πŸ•΄

An "open" Internet faces challenges from autocratic governance models. Policymakers should instead think about creating an Internet that's equitable, inclusive, and secure.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep130: Open the garage bay doors, HAL [Audio + Text] ⚠

I'm sorry, Dave. I'm afraid I can't... errr, no, hang on a minute, I can do that easily! Worldwide! Right now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-27779 β€Ό

AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30630 β€Ό

Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Best practices for Microsoft 365 business continuity πŸ“’

Discover how to mitigate the effects of large-scale, high-cost data loss disasters

πŸ“– Read

via "ITPro".
πŸ“’ Best practices for Google Workspace business continuity πŸ“’

Introducing a new model of business continuity that is focused on security and data protection

πŸ“– Read

via "ITPro".
πŸ•΄ Why the US Needs Quantum-Safe Cryptography Deployed Now πŸ•΄

Quantum computers might be a decade away, but guess how long it will take to switch systems over to post-quantum cryptography?

πŸ“– Read

via "Dark Reading".
πŸ•΄ Money Ransomware Group Enters Double-Extortion Fray πŸ•΄

Ransomware group uses API calls to spread throughout shared network resources, researchers say.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Remcos RAT Targets Tax Pros to Scurry Off With Workers' Filing Info πŸ•΄

Something exciting to liven up tax season: cybercriminals accessing sensitive personal information for individuals through the army of accountants preparing for Tax Day in the US.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-26412 β€Ό

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27748 β€Ό

BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26410 β€Ό

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20866 β€Ό

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27667 β€Ό

Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27747 β€Ό

BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access sensitive information such as configurations and recordings.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26414 β€Ό

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".