πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-25428 β€Ό

A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25958 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Justin Saad Simple Tooltips plugin <=Γ‚ 2.1.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23810 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SnapOrbital Panorama plugin <=Γ‚ 1.5 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22685 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <=Γ‚ v2.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28414 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ApexChat plugin <=Γ‚ 1.3.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25460 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodeSolz Easy Ad Manager plugin <=Γ‚ 1.0.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48020 β€Ό

Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the victim user's browser.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Malicious Chatbots Target Casinos in Southeast Asia πŸ•΄

Dubbed "ChattyGoblin," the China-backed actors use chatbots to scam Southeast Asian gambling companies.

πŸ“– Read

via "Dark Reading".
πŸ•΄ New Competition Focuses on Hardening Cryptosystems πŸ•΄

The Technology Innovation Institute’s year-long cryptographic challenge invites participants to assess concrete hardness of McEliece public-key encryption scheme.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Making Sure Lost Data Stays Lost πŸ•΄

Retired hardware and forgotten cloud virtual machines are a trove of insecure confidential data. Here's how to ameliorate that weakness.

πŸ“– Read

via "Dark Reading".
πŸ•΄ An Analyst View of XM Cyber’s Acquisition of Confluera πŸ•΄

The deal will enhance the capabilities of both companies and provide customers with a more comprehensive way to protect their digital assets.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-2457 β€Ό

Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32306 β€Ό

Time Tracker is an open source time tracking system. A time-based blind injection vulnerability existed in Time Tracker reports in versions prior to 1.22.13.5792. This was happening because the `reports.php` page was not validating all parameters in POST requests. Because some parameters were not checked, it was possible to craft POST requests with malicious SQL for Time Tracker database. This issue is fixed in version 1.22.13.5792. As a workaround, use the fixed code in `ttReportHelper.class.php` from version 1.22.13.5792.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32305 β€Ό

aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages missing schema qualifiers on privileged functions called by the aiven-extras extension. A low privileged user can create objects that collide with existing function names, which will then be executed instead. Exploiting this vulnerability could allow a low privileged user to acquire `superuser` privileges, which would allow full, unrestricted access to all data and database functions. And could lead to arbitrary code execution or data access on the underlying host as the `postgres` user. The issue has been patched as of version 1.1.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30247 β€Ό

File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25927 β€Ό

IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27863 β€Ό

IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2458 β€Ό

Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: High)

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ WordPress Plugin Used in 1M+ Websites Patched to Close Critical Bug πŸ•΄

The privilege escalation flaw is one in thousands that researchers have disclosed in recent years.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-20880 β€Ό

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25005 β€Ό

A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".