π’ The rise of identity-based cyber attacks and how to mitigate them π’
π Read
via "ITPro".
If identity-based cyber attacks are successful, they can give hackers the opportunity to infiltrate an entire network π Read
via "ITPro".
ITPro
The rise of identity-based cyber attacks and how to mitigate them
If identity-based cyber attacks are successful, they can give hackers the opportunity to infiltrate an entire network
π’ Microsoft Authenticator mandates number matching to counter MFA fatigue attacks π’
π Read
via "ITPro".
The added layer of complexity aims to keep social engineering at bay π Read
via "ITPro".
ITPro
Microsoft Authenticator mandates number matching to counter MFA fatigue attacks
The added layer of complexity aims to keep social engineering at bay
βΌ CVE-2023-2590 βΌ
π Read
via "National Vulnerability Database".
Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23863 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Black and White Digital Ltd TreePress Γ’β¬β Easy Family Trees & Ancestor Profiles plugin <=Γ 2.0.22 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24372 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in USB Memory Direct Simple Custom Author Profiles plugin <=Γ 1.0.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23884 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <=Γ 2.5.20 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-2591 βΌ
π Read
via "National Vulnerability Database".
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.7.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23664 βΌ
π Read
via "National Vulnerability Database".
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ConvertBox ConvertBox Auto Embed WordPress plugin <=Γ 1.0.19 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23883 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilityΓ in David Gwyer WP Content Filter plugin <=Γ 3.0.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23733 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Lazy Social Comments plugin <=Γ 2.0.4 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41640 βΌ
π Read
via "National Vulnerability Database".
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Rymera Web Co Wholesale Suite plugin <=Γ 2.1.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23732 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Disqus Conditional Load plugin <=Γ 11.0.6 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23734 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David Voswinkel Userlike Γ’β¬β WordPress Live Chat plugin <=Γ 2.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23862 βΌ
π Read
via "National Vulnerability Database".
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Vertical scroll recent post plugin <=Γ 14.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23793 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eightweb Interactive Read More Without Refresh plugin <=Γ 3.1 versions.π Read
via "National Vulnerability Database".
π΄ Half of npm Packages Vulnerable to Old-School Weapon: the 'Shift' Key π΄
π Read
via "Dark Reading".
For years, hackers could have tricked enterprises into downloading malware by simply de-capitalizing letters.π Read
via "Dark Reading".
Dark Reading
Npm Packages Vulnerable to Old-School Weapon: the 'Shift' Key
For years, hackers could have tricked enterprises into downloading malware by simply de-capitalizing letters in uppercase-named npm packages.
π΄ Royal Ransomware Expands to Target Linux, VMware ESXi π΄
π Read
via "Dark Reading".
The ransomware gang has also started using the BatLoader dropper and SEO poisoning for initial access.π Read
via "Dark Reading".
Dark Reading
Royal Ransomware Expands to Target Linux, VMware ESXi
The ransomware gang has also started using the BatLoader dropper and SEO poisoning for initial access.
βοΈ Feds Take Down 13 More DDoS-for-Hire Services βοΈ
π Read
via "Krebs on Security".
The U.S. Federal Bureau of Investigation (FBI) this week seized 13 domain names connected to βbooterβ services that let paying customers launch crippling distributed denial-of-service (DDoS) attacks. Ten of the domains are reincarnations of DDoS-for-hire services the FBI seized in December 2022, when it charged six U.S. men with computer crimes for allegedly operating booters.π Read
via "Krebs on Security".
Krebs on Security
Feds Take Down 13 More DDoS-for-Hire Services
The U.S. Federal Bureau of Investigation (FBI) this week seized 13 domain names connected to βbooterβ services that let paying customers launch crippling distributed denial-of-service (DDoS) attacks. Ten of the domains are reincarnations of DDoS-for-hireβ¦
π΄ Keep Your Company Cyber Competent Without Adding Cyber Anxiety π΄
π Read
via "Dark Reading".
With the right attitude, businesses can maximize employee satisfaction and protection, without sacrificing productivity.π Read
via "Dark Reading".
Dark Reading
Keep Your Company Cyber Competent Without Adding Cyber Anxiety
With the right attitude, businesses can maximize employee satisfaction and protection, without sacrificing productivity.
βΌ CVE-2023-31974 βΌ
π Read
via "National Vulnerability Database".
yasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29104 βΌ
π Read
via "National Vulnerability Database".
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The filename in the upload feature of the web based management of the affected device is susceptible to a path traversal vulnerability. This could allow an authenticated privileged remote attacker to overwrite any file the Linux user `ccuser` has write access to, or to download any file the Linux user `ccuser` has read-only access to.π Read
via "National Vulnerability Database".