🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2023-31669

WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").

📖 Read

via "National Vulnerability Database".
CVE-2023-23724

Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-23706

Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.

📖 Read

via "National Vulnerability Database".
1
CVE-2023-25707

Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-25472

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-25481

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions.

📖 Read

via "National Vulnerability Database".
🛠 Stegano 0.11.2 🛠

Stegano is a basic Python Steganography module. Stegano implements two methods of hiding: using the red portion of a pixel to hide ASCII messages, and using the Least Significant Bit (LSB) technique. It is possible to use a more advanced LSB method based on integers sets. The sets (Sieve of Eratosthenes, Fermat, Carmichael numbers, etc.) are used to select the pixels used to hide the information.

📖 Read

via "Packet Storm Security".
🕴 Bridgestone CISO: Lessons From Ransomware Attack Include Acting, Not Thinking 🕴

A February 2022 attack, knocked the giant tire maker's North American operations offline for several days.

📖 Read

via "Dark Reading".
🕴 Microsoft: BEC Attackers Evade 'Impossible Travel' Flags With Residential IP Addresses 🕴

Threat actors are circumventing geo-location-based security detections, using a combination of cybercrime-as-a-service platforms and the purchasing of local IP addresses.

📖 Read

via "Dark Reading".
CVE-2023-30440

IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption. IBM X-Force ID: 253175.

📖 Read

via "National Vulnerability Database".
1
CVE-2023-33359

Piwigo 13.6.0 is vulnerable to Cross Site Request Forgery (CSRF) in the "add tags" function.

📖 Read

via "National Vulnerability Database".
CVE-2023-25056

Cross-Site Request Forgery (CSRF) vulnerability in SlickRemix Feed Them Social plugin <= 3.0.2 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-33617

An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing target_addr parameter.

📖 Read

via "National Vulnerability Database".
CVE-2023-33361

Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.

📖 Read

via "National Vulnerability Database".
CVE-2023-26014

Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-46853

Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 5.0.4 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-23705

Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions.

📖 Read

via "National Vulnerability Database".
CVE-2022-46813

Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-26011

Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Read More Excerpt Link plugin <= 1.6 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-33599

EasyImages2.0 ? 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php.

📖 Read

via "National Vulnerability Database".
CVE-2022-46851

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.

📖 Read

via "National Vulnerability Database".