πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-38707 β€Ό

IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep133: Apple takes β€œtight-lipped” to a whole new level ⚠

Entertaining, educational, and all in plain English πŸŽ§πŸ“–

πŸ“– Read

via "Naked Security".
⚠ World Password Day: 2 + 2 = 4 ⚠

We've kept it short and simple, with no sermons, no judgmentalism, no tubthumping... and no BUY NOW buttons. Have a nice day!

πŸ“– Read

via "Naked Security".
⚠ PHP Packagist supply chain poisoned by hacker β€œlooking for a job” ⚠

I pwned you! Gizza job! You know it makes sense!

πŸ“– Read

via "Naked Security".
πŸ•΄ Attackers Route Malware Activity Over Popular CDNs πŸ•΄

One way to hide malicious activity is to make it look benign by blending in with regular traffic passing through content delivery networks (CDNs) and cloud service providers, according to a Netskope report.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-29659 β€Ό

A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26285 β€Ό

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM X-Force ID: 248418.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32269 β€Ό

An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However, in order for an attacker to exploit this, the system must have netrom routing configured or the attacker must have the CAP_NET_ADMIN capability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Apple Patches Bluetooth Flaw in AirPods, Beats πŸ•΄

Users can check for the updated firmware version of their wireless headphones in the Bluetooth settings of their iPhone, iPad, or Mac devices.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Judge Spares Former Uber CISO Jail Time Over 2016 Data Breach Charges πŸ•΄

Tell other CISO's "you got a break," judge says in handing down a three-year probation sentence to Joseph Sullivan.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-2427 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4914 β€Ό

IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43866 β€Ό

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239436.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2516 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Browser Isolation Adapts to Remote Work, Greater Cloud Usage πŸ•΄

As browsers become the center of many workers' days, isolation technologies shift to protecting the extended enterprise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Satori Unveils Universal Data Permissions Scanner, A Free Open-Source Tool that Sheds Light on Data Access Authorization πŸ•΄

Addressing data access blindspots commonly faced by enterprises, data security leader launches the first open-source authorization analysis tool to provide universal visibility into data access permissions across multiple data stores.

πŸ“– Read

via "Dark Reading".
πŸ•΄ KnowBe4 Launches Password Kit to Celebrate World Password Day πŸ•΄

KnowBe4 is offering a no-cost password kit to help end users practice good password hygiene and strengthen their defenses against social engineering.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-2553 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2551 β€Ό

PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2554 β€Ό

External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2552 β€Ό

Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1.

πŸ“– Read

via "National Vulnerability Database".