πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-33982 β€Ό

Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts. NOTE: the eavesdropping is typically impractical because BHP runs over an encrypted session that uses the Tor hidden service protocol.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33980 β€Ό

Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2875 β€Ό

A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the function 0x22E008u in the library PROCOBSRVESX.SYS of the component IoControlCode Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-229854 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2870 β€Ό

A vulnerability was found in EnTech Monitor Asset Manager 2.9. It has been declared as problematic. Affected by this vulnerability is the function 0x80002014 of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier VDB-229849 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘4
β€Ό CVE-2023-25029 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in utahta WP Social Bookmarking Light plugin <=Γ‚ 2.0.7 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32964 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in Made with Fuel Better Notifications for WP plugin <=Γ‚ 1.9.2 versions.

πŸ“– Read

via "National Vulnerability Database".
❀1πŸ‘1
β™ŸοΈ Phishing Domains Tanked After Meta Sued Freenom β™ŸοΈ

The number of phishing websites tied to domain name registrar Freenom dropped precipitously in the months surrounding a recent lawsuit from social networking giant Meta, which alleged the free domain name provider has a long history of ignoring abuse complaints about phishing websites while monetizing traffic to those abusive domains.

πŸ“– Read

via "Krebs on Security".
πŸ‘1
⚠ S3 Ep136: Navigating a manic malware maelstrom ⚠

Latest episode - listen now. Full transcript inside...

πŸ“– Read

via "Naked Security".
πŸ•΄ Travel-Themed Phishing, BEC Campaigns Get Smarter as Summer Season Arrives πŸ•΄

Phishing campaigns targeting travelers have evolved from simple, easy-to-spot fraud attempts to highly sophisticated operations.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-33440 β€Ό

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46882 β€Ό

The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-33720 β€Ό

mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Tesla Whistleblower Leaks 100GB of Data, Revealing Safety Complaints πŸ•΄

Informants have released data that includes thousands of safety complaints the company has received about its self-driving capability, as well as sensitive information regarding current and past employees.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-20868 β€Ό

NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32318 β€Ό

Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After successfully authenticating with any other account the previous session would be continued and the attacker would be authenticated as the previously logged in user. It is recommended that the Nextcloud Server is upgraded to 25.0.6 or 26.0.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 2 Lenses for Examining the Safety of Open Source Software πŸ•΄

Improving the security of open source repositories and keeping malicious components out requires a combination of technology and people.

πŸ“– Read

via "Dark Reading".
❀1
β€Ό CVE-2023-33197 β€Ό

Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.

πŸ“– Read

via "National Vulnerability Database".
❀1πŸ‘1
β€Ό CVE-2023-2854 β€Ό

BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21515 β€Ό

InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32321 β€Ό

CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the `ResourceUploader` object. Also reachable via `package_create`, `package_revise`, and `package_patch` via calls to `package_update`. Remote code execution via unsafe pickle loading, via Beaker's session store when configured to use the file session store backend. Potential DOS due to lack of a length check on the resource id. Information disclosure: A user with permission to create a resource can access any other resource on the system if they know the id, even if they don't have access to it. Resource overwrite: A user with permission to create a resource can overwrite any resource if they know the id, even if they don't have access to it. A user with permissions to create or edit a dataset can upload a resource with a specially crafted id to write the uploaded file in an arbitrary location. This can be leveraged to Remote Code Execution via Beaker's insecure pickle loading. All the above listed vulnerabilities have been fixed in CKAN 2.9.9 and CKAN 2.10.1. Users are advised to upgrade. There are no known workarounds for these issues.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘2