πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.3K subscribers
88.8K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-26057 β€Ό

An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25479 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Subscribe button plugin <=Γ‚ 1.3.7 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26841 β€Ό

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is currently logged in.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Building a Better SBOM πŸ•΄

Generating an SBOM is easy. It's generating one that's comprehensive and accurate that's hard.

πŸ“– Read

via "Dark Reading".
πŸ“’ How to reduce the risk of phishing and ransomware πŸ“’

Top security concerns and tips for mitigation

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-29779 β€Ό

Sengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send malicious Zigbee messages to a vulnerable device and cause crashes. After receiving the malicious command, the device will keep reporting its status and finally drain its battery after receiving the 'Set_short_poll_interval' command.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27105 β€Ό

A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via directory traversal.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2281 β€Ό

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

πŸ“– Read

via "National Vulnerability Database".
⚠ Double zero-day in Chrome and Edge – check your versions now! ⚠

Wouldn't it be handy if there were a single version number to check for in every Chromium-based browser, on every supported platform?

πŸ“– Read

via "Naked Security".
πŸ•΄ The Decline in Ransomware: Does It Actually Increase Risks for Organizations? πŸ•΄

Organizations need to remain vigilant and not take the decline as reason to cut back their cybersecurity strategies.

πŸ“– Read

via "Dark Reading".
⚠ PaperCut security vulnerabilities under active attack – vendor urges customers to patch ⚠

If you have the product, but you haven't patched - well, the crooks have now landed, so please don't delay. Do it today...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-31244 β€Ό

Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25484 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlâbe Simple Yearly Archive plugin <=Γ‚ 2.1.8 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47608 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <=Γ‚ 8.0.3.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25313 β€Ό

OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28847 β€Ό

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.0.0 prior to 24.0.11 and 25.0.0 prior to 25.0.5; as well as Nextcloud Server Enterprise 23.0.0 prior to 23.0.12.6, 24.0.0 prior to 24.0.11, and 25.0.0 prior to 25.0.5; an attacker is not restricted in verifying passwords of share links so they can just start brute forcing the password. Nextcloud Server 24.0.11 and 25.0.5 and Nextcloud Enterprise Server 23.0.12.6, 24.0.11, and 25.0.5 contain a fix for this issue. No known workarounds are available.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30402 β€Ό

YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29552 β€Ό

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25314 β€Ό

Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain sensitive information via the success parameter to /user.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Attackers Abuse PaperCut RCE Flaws to Take Over Enterprise Print Servers πŸ•΄

Customers should apply updates to the print management software used by more than 100 million organizations worldwide, with typical US customers found in the SLED sector.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 'Good' AI Is the Only Path to True Zero-Trust Architecture πŸ•΄

Ultimately AI will protect the enterprise, but it's up to the cybersecurity community to protect 'good' AI in order to get there, RSA's Rohit Ghai says.

πŸ“– Read

via "Dark Reading".