πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-33627 β€Ό

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33732 β€Ό

Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.

πŸ“– Read

via "National Vulnerability Database".
❀2
β€Ό CVE-2023-23954 β€Ό

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29159 β€Ό

Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2010-10010 β€Ό

A vulnerability classified as problematic has been found in Stars Alliance PsychoStats up to 3.2.2a. This affects an unknown part of the file upload/admin/login.php. The manipulation of the argument ref leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 3.2.2b is able to address this issue. The name of the patch is 5d3b7311fd5085ec6ea1b1bfa9a05285964e07e4. It is recommended to upgrade the affected component. The identifier VDB-230265 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4332 β€Ό

In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x aΓ‚ vulnerable firmware verification has been identified. Through physical access and hardware manipulation, an attacker might be able to bypass hardware-based code verification and thus inject and execute arbitrary code and gain full access of the device.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Barracuda network appliance vulnerability β€œactively exploited” for seven months πŸ“’

The company has issued a patch, but warned customers that the vulnerability left them exposed for over half a year

πŸ“– Read

via "ITPro".
πŸ“’ Amazon's Ring agrees to $5.8m settlement over alleged use of its cameras to spy on female customers πŸ“’

The firm will also pay $25m for allegations Alexa stored child voice recordings indefinitely

πŸ“– Read

via "ITPro".
πŸ•΄ Meet Charlotte, CrowdStrike's New Generative AI Assistant πŸ•΄

Charlotte AI is the latest security-based generative AI assistant to hit the market.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Top macOS Malware Threats Proliferate: Here Are 6 to Watch πŸ•΄

Apple's growing market share β€” in a shrinking PC market β€” and the growing use of Golang for malware development is pushing a gradual increase in malicious tools targeting macOS environments.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Dark Reading Launches Inaugural CISO Advisory Board πŸ•΄

Ten chief information security officers from a variety of verticals will provide valuable insights to Dark Reading on what they see as the industry's most pressing issues.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ SolarWinds Transforms Brand to Signify Ongoing Evolution, Portfolio Expansion, and Customer Empowerment πŸ•΄

Refreshed version of iconic SolarWinds logo and vibrant new brand color palette honor company’s historic success while highlighting future vision.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-22652 β€Ό

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files.This issue affects libeconf: before 0.5.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33546 β€Ό

janino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method. If the parser runs on user-supplied input, an attacker could supply content that causes the parser to crash due to a stack overflow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33544 β€Ό

hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43760 β€Ό

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is executed within another user's browser, allowing the attacker to steal sensitive information, manipulate web content, or perform other malicious activities on behalf of the victims. This could result in a user with write access to the affected areas being able to act on behalf of an administrator, once an administrator opens the affected web page.This issue affects Rancher: from >= 2.6.0 before < 2.6.13, from >= 2.7.0 before < 2.7.4.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  AIEngine 2.4.0 πŸ› 

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go network intrusion detection system engine. AIEngine also helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and so on.

πŸ“– Read

via "Packet Storm Security".
⚠ Serious Security: That KeePass β€œmaster password crack”, and what we can learn from it ⚠

Here, in an admittedly discursive nutshell, is the fascinating story of CVE-2023-32784. (Short version: Don't panic.)

πŸ“– Read

via "Naked Security".
❀1
πŸ•΄ Biometric Bypass: BrutePrint Makes Short Work of Fingerprint Security πŸ•΄

Bugs in the biometric protections on Android phones and iPhones allow the limit on the number of tries to unlock the devices with a fingerprint can be bypassed, allowing automated brute-force attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-33965 β€Ό

Brook is a cross-platform programmable network tool. The `tproxy` server is vulnerable to a drive-by command injection. An attacker may fool a victim into visiting a malicious web page which will trigger requests to the local `tproxy` service leading to remote code execution. A patch is available in version 20230606.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Ask Fitis, the Bear: Real Crooks Sign Their Malware β™ŸοΈ

Code-signing certificates are supposed to help authenticate the identity of software publishers, and provide cryptographic assurance that a signed piece of software has not been altered or tampered with. Both of these qualities make stolen or ill-gotten code-signing certificates attractive to cybercriminal groups, who prize their ability to add stealth and longevity to malicious software. This post is a deep dive on "Megatraffer," a veteran Russian hacker who has practically cornered the underground market for malware focused code-signing certificates since 2015.

πŸ“– Read

via "Krebs on Security".