πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-29659 β€Ό

A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26285 β€Ό

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM X-Force ID: 248418.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32269 β€Ό

An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However, in order for an attacker to exploit this, the system must have netrom routing configured or the attacker must have the CAP_NET_ADMIN capability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Apple Patches Bluetooth Flaw in AirPods, Beats πŸ•΄

Users can check for the updated firmware version of their wireless headphones in the Bluetooth settings of their iPhone, iPad, or Mac devices.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Judge Spares Former Uber CISO Jail Time Over 2016 Data Breach Charges πŸ•΄

Tell other CISO's "you got a break," judge says in handing down a three-year probation sentence to Joseph Sullivan.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-2427 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4914 β€Ό

IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43866 β€Ό

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239436.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2516 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Browser Isolation Adapts to Remote Work, Greater Cloud Usage πŸ•΄

As browsers become the center of many workers' days, isolation technologies shift to protecting the extended enterprise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Satori Unveils Universal Data Permissions Scanner, A Free Open-Source Tool that Sheds Light on Data Access Authorization πŸ•΄

Addressing data access blindspots commonly faced by enterprises, data security leader launches the first open-source authorization analysis tool to provide universal visibility into data access permissions across multiple data stores.

πŸ“– Read

via "Dark Reading".
πŸ•΄ KnowBe4 Launches Password Kit to Celebrate World Password Day πŸ•΄

KnowBe4 is offering a no-cost password kit to help end users practice good password hygiene and strengthen their defenses against social engineering.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-2553 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2551 β€Ό

PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2554 β€Ό

External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2552 β€Ό

Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2550 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-26519 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Benfica Publish to Schedule plugin <=Γ‚ 4.5.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26517 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <=Γ‚ 3.2.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25491 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilityΓ‚ in Samuel Marshall JCH Optimize plugin <=Γ‚ 3.2.2 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-24400 β€Ό

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Hu-manity.Co Cookie Notice & Compliance for GDPR / CCPA plugin <=Γ‚ 2.4.6 versions.

πŸ“– Read

via "National Vulnerability Database".