πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-23830 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <=Γ‚ 4.5.4 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ What's the Secret to Finding the Next Big Thing in Cybersecurity? πŸ•΄

Varun Badhwar, who has brought each of the three startups he founded to the finals of the RSAC Innovation Sandbox, talks about how to see around the corner.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Court Rejects Merck Insurers' Attempt to Refuse Coverage for NotPetya Damages πŸ•΄

Insurers unsuccessfully argued Merck's $1.4B in losses following NotPetya cyberattack fell under wartime exclusion.

πŸ“– Read

via "Dark Reading".
πŸ‘1
⚠ Tracked by hidden tags? Apple and Google unite to propose safety and security standards… ⚠

To bleat, or not to bleat, that is the question.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-25827 β€Ό

Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. This issue shares the same root cause as CVE-2018-13003, a reflected XSS vulnerability with the suggestion endpoint.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25826 β€Ό

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this vulnerability was previously disclosed as CVE-2020-35476. Regex validation that was implemented to restrict allowed input to the query API does not work as intended, allowing crafted commands to bypass validation.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ DNA Sequencing Equipment Vulnerability Adds New Twist to Medical Device Cyber Threats πŸ•΄

A vulnerability in a DNA sequencer highlights the expanded attack surface area of healthcare organizations but also shows that reporting of medical device vulnerabilities works.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google Chrome Drops Browser Lock Icon πŸ•΄

Chrome 117 will retire the lock icon and replace it with a "tune" icon, reflecting evolving cybersecurity standards.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Moonsense Raises $4.2M in Seed Funding and Introduces Next-Gen User Behavior and Network Intelligence Solution πŸ•΄

Hassle-free initial trial, harnesses digital body language and source data for enhanced fraud detection.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-30205 β€Ό

A stored cross-site scripting (XSS) vulnerability in DouPHP v1.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the unique_id parameter in /admin/article.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2069 β€Ό

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30300 β€Ό

An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1965 β€Ό

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39161 β€Ό

IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server, could allow an authenticated user to conduct spoofing attacks. A man-in-the-middle attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 235069.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1265 β€Ό

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0155 β€Ό

An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24744 β€Ό

Cross Site Scripting (XSS) vulnerability in Rediker Software AdminPlus 6.1.91.00 allows remote attackers to run arbitrary code via the onload function within the application DOM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-11197 β€Ό

In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0485 β€Ό

An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.

πŸ“– Read

via "National Vulnerability Database".