🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2023-32515

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-25698

Cross-Site Request Forgery (CSRF) vulnerability in Studio Wombat Shoppable Images plugin <= 1.2.3 versions.

📖 Read

via "National Vulnerability Database".
US offers $10m bounty for Russian ransomware suspect outed in indictment

"Up to $10 million for information that leads to the arrest and/or conviction of this defendant."

📖 Read

via "Naked Security".
🕴 Eagle Eye Networks and Brivo Announce $192M Investment — One of the Largest Ever in Cloud Physical Security 🕴

SECOM CO., LTD, a $15B enterprise and one of the largest security integration companies in the world, invests in the two global cloud physical security leaders, accelerating the use of AI and improving safety and security.

📖 Read

via "Dark Reading".
🕴 ActZero Teams Up With UScellular to Secure Mobile Devices From Ransomware Attacks 🕴

AI-powered cyber defense service protects against phishing attacks for businesses on unlimited handset plans.

📖 Read

via "Dark Reading".
🕴 3 Ways Hackers Use ChatGPT to Cause Security Headaches 🕴

As ChatGPT adoption grows, the industry needs to proceed with caution. Here's why.

📖 Read

via "Dark Reading".
🕴 LayerZero Labs Launches $15M Bug Bounty; Largest in the World 🕴

Launched in partnership with Immunefi, bounty to promote Web3 security.

📖 Read

via "Dark Reading".
CVE-2023-2790

A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-229374 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

📖 Read

via "National Vulnerability Database".
CVE-2023-2789

A vulnerability was found in GNU cflow 1.7. It has been rated as problematic. This issue affects the function func_body/parse_variable_declaration of the file parser.c. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier VDB-229373 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

📖 Read

via "National Vulnerability Database".
🕴 WithSecure Launches New Range of Incident Response and Readiness Services 🕴

New retainer provides expert support starting in the first 72 hours of the incident response process to contain the attack and improve preparedness for the future.

📖 Read

via "Dark Reading".
🕴 LexisNexis Risk Solutions Cybercrime Report Reveals 20% Annual Increase in Global Digital Attack Rate 🕴

Elevated attack rate expected to remain during 2023 as cybercrime becomes more sophisticated and widespread.

📖 Read

via "Dark Reading".
🕴 Once Again, Malware Discovered Hidden in npm 🕴

Turkorat-poisoned packages sat in the npm development library for months, researchers say.

📖 Read

via "Dark Reading".
🕴 Satori Augments Its Data Security Platform With Posture Management and Data Store Discovery Capabilities 🕴

With the new additions to Satori's Data Security Platform, companies gain unprecedented visibility to answer "Where is all my data?" and "Who has access to it?"

📖 Read

via "Dark Reading".
🕴 OX Security Launches OX-GPT, AppSec's First ChatGPT Integration 🕴

Customized fix recommendations and cut and paste code fixes dramatically reduce remediation times.

📖 Read

via "Dark Reading".
S3 Ep135: Sysadmin by day, extortionist by night

Laugh (sufficiently), learn (efficiently), and then let us know what you think in our comments (anonymously, if you wish)...

📖 Read

via "Naked Security".
🕴 Embedding Security by Design: A Shared Responsibility 🕴

Security by design can't be just a best practice — it has to become a fundamental part of software development.

📖 Read

via "Dark Reading".
🕴 Microsoft Azure VMs Highjacked in Cloud Cyberattack 🕴

Cybercrime group that often uses smishing for initial access bypassed traditional OS targeting and evasion techniques to directly gain access to the cloud.

📖 Read

via "Dark Reading".
🕴 10 Types of AI Attacks CISOs Should Track 🕴

Risk from artificial intelligence vectors presents a growing concern among security professionals in 2023.

📖 Read

via "Dark Reading".
CVE-2023-31871

OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security controls in place preventing creation of a file in a non-owned directory, or as the root user. However, these controls can be carefully bypassed to allow for an arbitrary file write as root.

📖 Read

via "National Vulnerability Database".
CVE-2023-2799

A vulnerability, which was classified as problematic, has been found in cnoa OA up to 5.1.1.5. Affected by this issue is some unknown functionality of the file /index.php?app=main&func=passport&action=login. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-229376. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

📖 Read

via "National Vulnerability Database".
CVE-2023-2800

Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.

📖 Read

via "National Vulnerability Database".