πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-23820 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <=Γ‚ 4.5.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25796 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Include WP BaiDu Submit plugin <=Γ‚ 1.2.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25798 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Olevmedia Olevmedia Shortcodes plugin <=Γ‚ 1.1.9 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40318 β€Ό

An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (instead of 2) in this 0xff case. NOTE: this behavior occurs in bgp_open_option_parse in the bgp_open.c file, a different location (with a different attack vector) relative to CVE-2022-40302.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1383 β€Ό

An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible.This issue affects:Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23708 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <=Γ‚ 3.9.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1384 β€Ό

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be runThis issue affects:Amazon Fire TV Stick 3rd genΓ‚ versions prior to 6.2.9.5.Insignia TV with FireOSΓ‚ versions prior to 7.6.3.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1385 β€Ό

Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services.This issue affects:Amazon Fire TV Stick 3rd genΓ‚ versions prior to 6.2.9.5.Insignia TV with FireOSΓ‚ 7.6.3.3.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Anatomy of a Malicious Package Attack πŸ•΄

Malicious packages are hard to avoid and hard to detect β€” unless you know what to look for.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-26017 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <=Γ‚ 2.5.10.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23875 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Himanshu Bing Site Verification plugin using Meta Tag plugin <=Γ‚ 1.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23881 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GreenTreeLabs Circles Gallery plugin <=Γ‚ 1.0.10 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25967 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo plugin <=Γ‚ 6.0.2.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23830 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <=Γ‚ 4.5.4 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ What's the Secret to Finding the Next Big Thing in Cybersecurity? πŸ•΄

Varun Badhwar, who has brought each of the three startups he founded to the finals of the RSAC Innovation Sandbox, talks about how to see around the corner.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Court Rejects Merck Insurers' Attempt to Refuse Coverage for NotPetya Damages πŸ•΄

Insurers unsuccessfully argued Merck's $1.4B in losses following NotPetya cyberattack fell under wartime exclusion.

πŸ“– Read

via "Dark Reading".
πŸ‘1
⚠ Tracked by hidden tags? Apple and Google unite to propose safety and security standards… ⚠

To bleat, or not to bleat, that is the question.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-25827 β€Ό

Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. This issue shares the same root cause as CVE-2018-13003, a reflected XSS vulnerability with the suggestion endpoint.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25826 β€Ό

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this vulnerability was previously disclosed as CVE-2020-35476. Regex validation that was implemented to restrict allowed input to the query API does not work as intended, allowing crafted commands to bypass validation.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ DNA Sequencing Equipment Vulnerability Adds New Twist to Medical Device Cyber Threats πŸ•΄

A vulnerability in a DNA sequencer highlights the expanded attack surface area of healthcare organizations but also shows that reporting of medical device vulnerabilities works.

πŸ“– Read

via "Dark Reading".