๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.9K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-2859 โ€ผ

Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-0357 โ€ผ

Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM.This issue affects:Bitdefender Total Securityversions prior to 26.0.10.45.Bitdefender Internet Securityversions prior to 26.0.10.45.Bitdefender Antivirus Plusversions prior to 26.0.10.45.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1424 โ€ผ

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด 5 Questions to Ask When Evaluating a New Cybersecurity Technology ๐Ÿ•ด

Any new cybersecurity technology should be not just a neutral addition to a security stack but a benefit to the other technologies or people managing them.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-2750 โ€ผ

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection.This issue affects E-municipality: before 6.05.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-33009 โ€ผ

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-33937 โ€ผ

Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-33010 โ€ผ

A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2065 โ€ผ

Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass.This issue affects Cargo Tracking System: before 3558f28 .

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Israeli Shipping, Logistics Companies Targeted in Watering Hole Attacks ๐Ÿ•ด

Researchers say the Iranian nation-state actor known as Tortoiseshell could be behind the attacks.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด How Universities Can Bridge Cybersecurity's Gender Gap ๐Ÿ•ด

It's time to invest in initiatives that engage young women in cybersecurity early and often.

๐Ÿ“– Read

via "Dark Reading".
โš  PyPI open-source code repository deals with manic malware maelstrom โš 

Controlled outage used to keep malware marauders from gumming up the works. Learn what you can do to help in future...

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด OAuth Flaw in Expo Platform Affects Hundreds of Third-Party Sites, Apps ๐Ÿ•ด

A cybersecurity vulnerability found in an implementation of the social login functionality opens the door to account takeovers and more.

๐Ÿ“– Read

via "Dark Reading".
โš  Ransomware tales: The MitM attack that really had a Man in the Middle โš 

Another traitorous insider, busted by system logs that gave his game away.

๐Ÿ“– Read

via "Naked Security".
โ€ผ CVE-2022-46816 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <=ร‚ 1.1.4 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-47447 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <=ร‚ 3.3.8 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-47446 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps รขโ‚ฌโ€œ LotsOfLocales plugin <=ร‚ 3.98.7 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-47180 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Kopa Theme Kopa Framework plugin <=ร‚ 1.3.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-46794 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in weightbasedshipping.Com WooCommerce Weight Based Shipping plugin <=ร‚ 5.4.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25028 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in chuyencode CC Custom Taxonomy plugin <=ร‚ 1.0.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1174 โ€ผ

This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.

๐Ÿ“– Read

via "National Vulnerability Database".