πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-27889 β€Ό

Cross-site request forgery (CSRF) vulnerability in LIQUID SPEECH BALLOON versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of a user and to perform unintended operations by having a user view a malicious page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22711 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Agent Evolution IMPress Listings plugin <=Γ‚ 2.6.2 versions.

πŸ“– Read

via "National Vulnerability Database".
⚠ Low-level motherboard security keys leaked in MSI breach, claim researchers ⚠

What can you do if someone steals your keys but you can't change the lock? We explain the dilemma in plain English.

πŸ“– Read

via "Naked Security".
πŸ“’ Capita cyber attack could cost firm up to $25 million in fees πŸ“’

Capita’s costs in the wake of a cyber attack could exceed expectations, experts have warned

πŸ“– Read

via "ITPro".
πŸ“’ How the channel can help secure the future of work πŸ“’

Hybrid work security issues pose challenges for businesses, but this is where the channel has an opportunity to step in and support partners

πŸ“– Read

via "ITPro".
⚠ Bootkit zero-day fix – is this Microsoft’s most cautious patch ever? ⚠

When blocking buggy bootup modules, you have to be really careful not to lock your keys inside the car...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-47137 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPManageNinja LLC Ninja Tables plugin <=Γ‚ 4.3.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46861 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Zia Imtiaz Custom Login Page Styler for WordPress plugin <=Γ‚ 6.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47600 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Mass Email To users plugin <=Γ‚ 1.1.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47423 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ulf Benjaminsson WP-dTree plugin <=Γ‚ 4.4.5 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27856 β€Ό

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <=Γ‚ 4.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47436 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MantraBrain Yatra plugin <=Γ‚ 2.1.14 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46819 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Continuous announcement scroller plugin <=Γ‚ 13.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47606 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tim Stephenson WP-CORS plugin <=Γ‚ 0.2.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47441 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <=Γ‚ 1.7.0.10 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46817 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Flyzoo Flyzoo Chat plugin <=Γ‚ 2.3.3 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47587 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <=Γ‚ 1.4.5 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33961 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WaspThemes Visual CSS Style Editor plugin <=Γ‚ 7.5.8 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47590 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fugu Maintenance Switch plugin <=Γ‚ 1.5.2 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ“’ US reveals bespoke tool that took down Russian malware operation πŸ“’

Snake had been used to steal NATO countries’ data for 20 years

πŸ“– Read

via "ITPro".
πŸ•΄ New Startup SquareX Targets Brower-Based Attacks πŸ•΄

SquareX runs headless browsers in data centers on the user's behalf so that threats never reach the user's machine.

πŸ“– Read

via "Dark Reading".