🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2022-45457

Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984.

📖 Read

via "National Vulnerability Database".
CVE-2022-45453

TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.

📖 Read

via "National Vulnerability Database".
CVE-2023-27423

Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Auto Prune Posts plugin <= 1.8.0 versions.

📖 Read

via "National Vulnerability Database".
CVE-2022-4418

Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40208.

📖 Read

via "National Vulnerability Database".
CVE-2023-23667

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-23999

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.

📖 Read

via "National Vulnerability Database".
CVE-2022-47157

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Don Benjamin WP Custom Fields Search plugin <= 1.2.34 versions.

📖 Read

via "National Vulnerability Database".
CVE-2022-45458

Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984.

📖 Read

via "National Vulnerability Database".
CVE-2022-45459

Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.

📖 Read

via "National Vulnerability Database".
CVE-2023-2782

Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.3.1-38.

📖 Read

via "National Vulnerability Database".
CVE-2022-45452

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acronis Cyber Protect 15 (Windows) before build 30984.

📖 Read

via "National Vulnerability Database".
CVE-2022-45450

Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984.

📖 Read

via "National Vulnerability Database".
CVE-2023-31233

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Haoqisir Baidu Tongji generator plugin <= 1.0.2 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-30780

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TheGuideX User IP and Location plugin <= 2.2 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-27430

Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Mass Delete Unused Tags plugin <= 2.0.0 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-32515

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-25698

Cross-Site Request Forgery (CSRF) vulnerability in Studio Wombat Shoppable Images plugin <= 1.2.3 versions.

📖 Read

via "National Vulnerability Database".
US offers $10m bounty for Russian ransomware suspect outed in indictment

"Up to $10 million for information that leads to the arrest and/or conviction of this defendant."

📖 Read

via "Naked Security".
🕴 Eagle Eye Networks and Brivo Announce $192M Investment — One of the Largest Ever in Cloud Physical Security 🕴

SECOM CO., LTD, a $15B enterprise and one of the largest security integration companies in the world, invests in the two global cloud physical security leaders, accelerating the use of AI and improving safety and security.

📖 Read

via "Dark Reading".
🕴 ActZero Teams Up With UScellular to Secure Mobile Devices From Ransomware Attacks 🕴

AI-powered cyber defense service protects against phishing attacks for businesses on unlimited handset plans.

📖 Read

via "Dark Reading".
🕴 3 Ways Hackers Use ChatGPT to Cause Security Headaches 🕴

As ChatGPT adoption grows, the industry needs to proceed with caution. Here's why.

📖 Read

via "Dark Reading".