πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-25792 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XiaoMac WP Open Social plugin <=Γ‚ 5.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25784 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bon Plan Gratos Sticky Ad Bar pluginΓ‚ <= 1.3.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25797 β€Ό

Auth. Stored Cross-Site Scripting (XSS) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <=Γ‚ 4.1.2 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Palo Alto Networks Unveils New Cloud Firewall for Azure πŸ•΄

The next-generation cloud firewall is a fully managed Azure-native ISV service.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Hotels at Risk From Bug in Oracle Property Management Software πŸ•΄

Oracle's characterization of the vulnerability in its Opera software as complex and hard to exploit is incorrect, researchers who found the flaw and reported it say.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Meta Expunges Multiple APT, Cybercrime Groups from Facebook, Instagram πŸ•΄

The company has removed three APTs and six potentially criminal networks from its platforms who leveraged elaborate campaigns of fake personas and profiles to lure and compromise users.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Legitimate Software Abuse: A Disturbing Trend in Ransomware Attacks πŸ•΄

Build a culture of security so that everyone is on the lookout for suspect behavior. Implement least privilege, improve visibility.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-40302 β€Ό

An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (instead of 2) in this 0xff case.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22713 β€Ό

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <=Γ‚ 2.1.8 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43681 β€Ό

An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option length octet (or the option length word, in case of an extended OPEN message), the FRR code reads of out of the bounds of the packet, throwing a SIGABRT signal and exiting. This results in a bgpd daemon restart, causing a Denial-of-Service condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23820 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <=Γ‚ 4.5.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25796 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Include WP BaiDu Submit plugin <=Γ‚ 1.2.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25798 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Olevmedia Olevmedia Shortcodes plugin <=Γ‚ 1.1.9 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40318 β€Ό

An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (instead of 2) in this 0xff case. NOTE: this behavior occurs in bgp_open_option_parse in the bgp_open.c file, a different location (with a different attack vector) relative to CVE-2022-40302.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1383 β€Ό

An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible.This issue affects:Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23708 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <=Γ‚ 3.9.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1384 β€Ό

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be runThis issue affects:Amazon Fire TV Stick 3rd genΓ‚ versions prior to 6.2.9.5.Insignia TV with FireOSΓ‚ versions prior to 7.6.3.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1385 β€Ό

Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services.This issue affects:Amazon Fire TV Stick 3rd genΓ‚ versions prior to 6.2.9.5.Insignia TV with FireOSΓ‚ 7.6.3.3.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Anatomy of a Malicious Package Attack πŸ•΄

Malicious packages are hard to avoid and hard to detect β€” unless you know what to look for.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-26017 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <=Γ‚ 2.5.10.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23875 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Himanshu Bing Site Verification plugin using Meta Tag plugin <=Γ‚ 1.0 versions.

πŸ“– Read

via "National Vulnerability Database".