πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-33507 β€Ό

KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30285 β€Ό

An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Mirai Variant Opens Tenda, Zyxel Gear to RCE, DDoS πŸ•΄

Researchers have observed several cyberattacks leveraging a botnet called IZ1H9, which exploits vulnerabilities in exposed devices and servers running on Linux.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34224 β€Ό

In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3014 β€Ό

A vulnerability, which was classified as problematic, was found in BeipyVideoResolution up to 2.6. Affected is an unknown function of the file admin/admincore.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-230358 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ New eID Scheme Gives EU Citizens Easy Access to Public Services Online πŸ•΄

The European Commission voted a new electronic identification scheme that creates new opportunities for EU citizens and businesses.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Checkmarx Announces GenAI-powered AppSec Platform, Empowering Developers and AppSec Teams to Find and Fix Vulnerabilities Faster πŸ•΄

Powered by GPT-4, innovative new AI-driven capabilities lower application security (AppSec) risk and help security teams "shift everywhere" with speed and accuracy.

πŸ“– Read

via "Dark Reading".
❀1
⚠ Serious Security: That KeePass β€œmaster password crack”, and what we can learn from it ⚠

Here, in an admittedly discursive nutshell, is the fascinating story of CVE-2023-32784. (Short version: Don't panic.)

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-29747 β€Ό

Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened. Depending on how the data is used, this can result in various attack consequences, such as ad display exceptions.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘2
β€Ό CVE-2023-3021 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Ways to Help Cybersecurity's Essential Workers Avoid Burnout πŸ•΄

To support and retain the people who protect assets against bad actors, organizations should create a more defensible environment.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ MacOS 'Migraine' Bug: Big Headache for Device System Integrity πŸ•΄

Microsoft says the vulnerability could allow cyberattackers with root access to bypass security protections and install malware.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-35746 β€Ό

Windows Digital Media Receiver Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33967 β€Ό

EaseProbe is a tool that can do health/status checking. An SQL injection issue was discovered in EaseProbe before 2.1.0 when using MySQL/PostgreSQL data checking. This problem has been fixed in v2.1.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Can Cloud Services Encourage Better Login Security? Netflix's Accidental Model πŸ•΄

Netflix's unpopular password-sharing policy change had a positive cybersecurity silver lining. Can more B2C service providers nudge their users toward secure authentication?

πŸ“– Read

via "Dark Reading".
πŸ•΄ Yet Another Toyota Cloud Data Breach Jeopardizes Thousands of Customers πŸ•΄

The newly found misconfigured cloud services are discovered just two weeks after an initial data breach affecting millions came to light.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-33627 β€Ό

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33732 β€Ό

Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.

πŸ“– Read

via "National Vulnerability Database".
❀2
β€Ό CVE-2023-23954 β€Ό

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29159 β€Ό

Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2010-10010 β€Ό

A vulnerability classified as problematic has been found in Stars Alliance PsychoStats up to 3.2.2a. This affects an unknown part of the file upload/admin/login.php. The manipulation of the argument ref leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 3.2.2b is able to address this issue. The name of the patch is 5d3b7311fd5085ec6ea1b1bfa9a05285964e07e4. It is recommended to upgrade the affected component. The identifier VDB-230265 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".